* Kernel panic with bridge networking
From: Massimo Cetra @ 2012-04-12 12:30 UTC (permalink / raw)
To: netdev
[-- Attachment #1: Type: text/plain, Size: 729 bytes --]
Hello,
i am experiencing a panic whose logs are attached (grabbed with netconsole).
They look quite similar to what has been described here
http://www.spinics.net/lists/linux-net/msg17689.html
The patch proposed as the solution (commit
6b1e960fdbd75dcd9bcc3ba5ff8898ff1ad30b6e) seems to be applied (even with
small differences) but the problem persists.
The kernel is a debian linux-image-3.2.0-2-amd64 version 3.2.12-1
Any hint ?
I have checked the changelog of 3.2.13 and 3.2.14 and it doesn't seems
to be any commit regarding such problems.
Massimo Cetra
P.S.1: Please CC me as i'm not subscribed.
P.S.2: this bug has been submitted to debian as well
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668511
[-- Attachment #2: BUG1.txt --]
[-- Type: text/plain, Size: 25653 bytes --]
Apr 12 12:10:08 lamu [71020.539961] BUG: unable to handle kernel
Apr 12 12:10:08 NULL pointer dereference
Apr 12 12:10:08 lamu at 0000000000000018
Apr 12 12:10:08 lamu [71020.555654] IP:
Apr 12 12:10:08 lamu [<ffffffffa02e9336>] br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 12:10:08 lamu [71020.569755] PGD 0
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.573785] Oops: 0000 [#1]
Apr 12 12:10:08 SMP
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.580257] CPU 0
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.583912] Modules linked in:
Apr 12 12:10:08 lamu ipt_MASQUERADE
Apr 12 12:10:08 lamu iptable_nat
Apr 12 12:10:08 lamu nf_nat
Apr 12 12:10:08 lamu nf_conntrack_ipv4
Apr 12 12:10:08 lamu nf_defrag_ipv4
Apr 12 12:10:08 lamu ip_vs_rr
Apr 12 12:10:08 lamu ip_vs
Apr 12 12:10:08 lamu nf_conntrack
Apr 12 12:10:08 lamu libcrc32c
Apr 12 12:10:08 lamu ip6table_filter
Apr 12 12:10:08 lamu ip6_tables
Apr 12 12:10:08 lamu iptable_filter
Apr 12 12:10:08 lamu ip_tables
Apr 12 12:10:08 lamu ebtable_nat
Apr 12 12:10:08 lamu ebtables
Apr 12 12:10:08 lamu x_tables
Apr 12 12:10:08 lamu crc32c
Apr 12 12:10:08 lamu drbd
Apr 12 12:10:08 lamu lru_cache
Apr 12 12:10:08 lamu cn
Apr 12 12:10:08 lamu sit
Apr 12 12:10:08 lamu tunnel4
Apr 12 12:10:08 lamu tun
Apr 12 12:10:08 lamu bridge
Apr 12 12:10:08 lamu stp
Apr 12 12:10:08 lamu virtio_net
Apr 12 12:10:08 lamu virtio_blk
Apr 12 12:10:08 lamu virtio_rng
Apr 12 12:10:08 lamu rng_core
Apr 12 12:10:08 lamu virtio_pci
Apr 12 12:10:08 lamu virtio_ring
Apr 12 12:10:08 lamu virtio
Apr 12 12:10:08 lamu kvm_intel
Apr 12 12:10:08 lamu kvm
Apr 12 12:10:08 lamu ipmi_devintf
Apr 12 12:10:08 lamu ipmi_poweroff
Apr 12 12:10:08 lamu ipmi_si
Apr 12 12:10:08 lamu ipmi_watchdog
Apr 12 12:10:08 lamu ipmi_msghandler
Apr 12 12:10:08 lamu netconsole
Apr 12 12:10:08 lamu configfs
Apr 12 12:10:08 lamu loop
Apr 12 12:10:08 lamu option
Apr 12 12:10:08 lamu usb_wwan
Apr 12 12:10:08 lamu usbserial
Apr 12 12:10:08 lamu uas
Apr 12 12:10:08 lamu snd_pcm
Apr 12 12:10:08 lamu snd_page_alloc
Apr 12 12:10:08 lamu snd_timer
Apr 12 12:10:08 lamu snd
Apr 12 12:10:08 lamu iTCO_wdt
Apr 12 12:10:08 lamu iTCO_vendor_support
Apr 12 12:10:08 lamu psmouse
Apr 12 12:10:08 lamu i7core_edac
Apr 12 12:10:08 lamu edac_core
Apr 12 12:10:08 lamu processor
Apr 12 12:10:08 lamu button
Apr 12 12:10:08 lamu soundcore
Apr 12 12:10:08 lamu joydev
Apr 12 12:10:08 lamu serio_raw
Apr 12 12:10:08 lamu pcspkr
Apr 12 12:10:08 lamu evdev
Apr 12 12:10:08 lamu dcdbas
Apr 12 12:10:08 lamu thermal_sys
Apr 12 12:10:08 lamu ext3
Apr 12 12:10:08 lamu mbcache
Apr 12 12:10:08 lamu jbd
Apr 12 12:10:08 lamu dm_mod
Apr 12 12:10:08 lamu sr_mod
Apr 12 12:10:08 lamu cdrom
Apr 12 12:10:08 lamu ses
Apr 12 12:10:08 lamu sd_mod
Apr 12 12:10:08 lamu usbhid
Apr 12 12:10:08 lamu hid
Apr 12 12:10:08 lamu crc_t10dif
Apr 12 12:10:08 lamu enclosure
Apr 12 12:10:08 lamu ata_generic
Apr 12 12:10:08 lamu uhci_hcd
Apr 12 12:10:08 lamu ata_piix
Apr 12 12:10:08 lamu ehci_hcd
Apr 12 12:10:08 lamu libata
Apr 12 12:10:08 lamu usbcore
Apr 12 12:10:08 lamu megaraid_sas
Apr 12 12:10:08 lamu scsi_mod
Apr 12 12:10:08 lamu usb_common
Apr 12 12:10:08 lamu bnx2
Apr 12 12:10:08 lamu [last unloaded: usb_storage]
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.733498]
Apr 12 12:10:08 lamu [71020.736475] Pid: 6997, comm: kvm Not tainted 3.2.0-2-amd64 #1
Apr 12 12:10:08 lamu Dell Inc. PowerEdge R410
Apr 12 12:10:08 lamu /0N051F
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.753554] RIP: 0010:[<ffffffffa02e9336>]
Apr 12 12:10:08 lamu [<ffffffffa02e9336>] br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 12:10:08 lamu [71020.772519] RSP: 0018:ffff88042fc03b18 EFLAGS: 00010293
Apr 12 12:10:08 lamu [71020.783126] RAX: 0000000000000000 RBX: ffff8802c3f911c0 RCX: 00000001010dee01
Apr 12 12:10:08 lamu [71020.797376] RDX: ffffffffa02e9308 RSI: 0000000000000282 RDI: ffff8802c3f911c0
Apr 12 12:10:08 lamu [71020.811629] RBP: ffff8802269c0000 R08: 0000000000000000 R09: ffff88042fc03ad0
Apr 12 12:10:08 lamu [71020.825878] R10: ffffffff8165aac0 R11: ffffffff8165aac0 R12: 0000000000000000
Apr 12 12:10:08 lamu [71020.840127] R13: ffff880424a40002 R14: ffff8802ca545c00 R15: ffff880424a40000
Apr 12 12:10:08 lamu [71020.854379] FS: 00007f7e7613d900(0000) GS:ffff88042fc00000(0000) knlGS:0000000000000000
Apr 12 12:10:08 lamu [71020.870553] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Apr 12 12:10:08 lamu [71020.882027] CR2: 0000000000000018 CR3: 00000003e0369000 CR4: 00000000000026e0
Apr 12 12:10:08 lamu [71020.896276] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
Apr 12 12:10:08 lamu [71020.910527] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Apr 12 12:10:08 lamu [71020.924778] Process kvm (pid: 6997, threadinfo ffff8803d1f1e000, task ffff88042707c040)
Apr 12 12:10:08 lamu [71020.940776] Stack:
Apr 12 12:10:08 lamu [71020.944796] ffffffff80000000
Apr 12 12:10:08 lamu ffffffffa02e96db
Apr 12 12:10:08 lamu ffff8802c3f911c0
Apr 12 12:10:08 lamu ffff8802269c0000
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.959629] ffff88022799c000
Apr 12 12:10:08 lamu ffffffffa02e9a67
Apr 12 12:10:08 lamu ffff880480000000
Apr 12 12:10:08 lamu 0000000280000000
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.974464] ffff8802c3f911c0
Apr 12 12:10:08 lamu ffffffffa02efcd0
Apr 12 12:10:08 lamu ffffffff81691190
Apr 12 12:10:08 lamu 0000000000000002
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.989299] Call Trace:
Apr 12 12:10:08 lamu [71020.994185] <IRQ>
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71020.998394] [<ffffffffa02e96db>] ? br_parse_ip_options+0x3d/0x19a [bridge]
Apr 12 12:10:08 lamu [71021.012302] [<ffffffffa02e9a67>] ? br_nf_forward_ip+0x1c0/0x1d4 [bridge]
Apr 12 12:10:08 lamu [71021.025863] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 12:10:08 lamu [71021.036474] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:08 lamu [71021.048994] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:08 lamu [71021.061510] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 12:10:08 lamu [71021.072643] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:08 lamu [71021.085162] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:08 lamu [71021.098894] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:08 lamu [71021.111413] [<ffffffffa02e485e>] ? NF_HOOK.constprop.8+0x3c/0x56 [bridge]
Apr 12 12:10:08 lamu [71021.125144] [<ffffffffa02e49f2>] ? br_forward+0x16/0x5a [bridge]
Apr 12 12:10:08 lamu [71021.137318] [<ffffffffa02e551b>] ? br_handle_frame_finish+0x1a1/0x20f [bridge]
Apr 12 12:10:08 lamu [71021.151934] [<ffffffffa02e95ff>] ? br_nf_pre_routing_finish+0x1d0/0x1dd [bridge]
Apr 12 12:10:08 lamu [71021.166896] [<ffffffffa02e8ff0>] ? NF_HOOK_THRESH+0x3b/0x55 [bridge]
Apr 12 12:10:08 lamu [71021.179764] [<ffffffffa02e9f58>] ? br_nf_pre_routing+0x3e8/0x3f5 [bridge]
Apr 12 12:10:08 lamu [71021.193495] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 12:10:08 lamu [71021.204106] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:08 lamu [71021.217837] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 12:10:08 lamu [71021.228967] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:08 lamu [71021.242700] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:08 lamu [71021.256433] [<ffffffffa02e5360>] ? NF_HOOK.constprop.4+0x3c/0x56 [bridge]
Apr 12 12:10:08 lamu [71021.270165] [<ffffffff810135ad>] ? paravirt_read_tsc+0x5/0x8
Apr 12 12:10:08 lamu [71021.281642] [<ffffffff81013622>] ? read_tsc+0x5/0x14
Apr 12 12:10:08 lamu [71021.291733] [<ffffffffa02e573c>] ? br_handle_frame+0x1b3/0x1cb [bridge]
Apr 12 12:10:08 lamu [71021.305120] [<ffffffffa02e5589>] ? br_handle_frame_finish+0x20f/0x20f [bridge]
Apr 12 12:10:08 lamu [71021.319736] [<ffffffff812890cd>] ? __netif_receive_skb+0x324/0x41f
Apr 12 12:10:08 lamu [71021.332251] [<ffffffff81289234>] ? process_backlog+0x6c/0x123
Apr 12 12:10:08 lamu [71021.343901] [<ffffffff8128b11a>] ? net_rx_action+0xa1/0x1af
Apr 12 12:10:08 lamu [71021.355206] [<ffffffff81037013>] ? test_tsk_need_resched+0xa/0x13
Apr 12 12:10:08 lamu [71021.367552] [<ffffffff8104be98>] ? __do_softirq+0xb9/0x177
Apr 12 12:10:08 lamu [71021.378685] [<ffffffff8135026c>] ? call_softirq+0x1c/0x30
Apr 12 12:10:08 lamu [71021.389640] <EOI>
Apr 12 12:10:08 lamu
Apr 12 12:10:08 lamu [71021.393845] [<ffffffff8100f8e5>] ? do_softirq+0x3c/0x7b
Apr 12 12:10:08 lamu [71021.404454] [<ffffffff8128b40a>] ? netif_rx_ni+0x1e/0x27
Apr 12 12:10:08 lamu [71021.415239] [<ffffffffa02f6721>] ? tun_get_user+0x39a/0x3c2 [tun]
Apr 12 12:10:09 lamu [71021.427583] [<ffffffffa02f6a66>] ? tun_chr_poll+0xcd/0xcd [tun]
Apr 12 12:10:09 lamu [71021.439579] [<ffffffffa02f6ac4>] ? tun_chr_aio_write+0x5e/0x79 [tun]
Apr 12 12:10:09 lamu [71021.452445] [<ffffffff810f95d4>] ? do_sync_readv_writev+0x9a/0xd7
Apr 12 12:10:09 lamu [71021.464788] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 12:10:09 lamu [71021.475917] [<ffffffff810f8c56>] ? do_sync_read+0xab/0xe3
Apr 12 12:10:09 lamu [71021.486875] [<ffffffff81061a94>] ? enqueue_hrtimer+0x43/0x6a
Apr 12 12:10:09 lamu [71021.498350] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 12:10:09 lamu [71021.509483] [<ffffffff81162569>] ? security_file_permission+0x16/0x2d
Apr 12 12:10:09 lamu [71021.522520] [<ffffffff810f9838>] ? do_readv_writev+0xaf/0x11c
Apr 12 12:10:09 lamu [71021.534173] [<ffffffff8112abb6>] ? eventfd_ctx_read+0x162/0x174
Apr 12 12:10:09 lamu [71021.546174] [<ffffffff8103f467>] ? try_to_wake_up+0x197/0x197
Apr 12 12:10:09 lamu [71021.557825] [<ffffffff810f9a0d>] ? sys_writev+0x45/0x90
Apr 12 12:10:09 lamu [71021.568437] [<ffffffff8134e012>] ? system_call_fastpath+0x16/0x1b
Apr 12 12:10:09 lamu [71021.580778] Code:
Apr 12 12:10:09 53
Apr 12 12:10:09 48
Apr 12 12:10:09 89
Apr 12 12:10:09 fb
Apr 12 12:10:09 48
Apr 12 12:10:09 83
Apr 12 12:10:09 ec
Apr 12 12:10:09 10
Apr 12 12:10:09 66
Apr 12 12:10:09 81
Apr 12 12:10:09 7f
Apr 12 12:10:09 7e
Apr 12 12:10:09 08
Apr 12 12:10:09 06
Apr 12 12:10:09 4c
Apr 12 12:10:09 8b
Apr 12 12:10:09 a7
Apr 12 12:10:09 98
Apr 12 12:10:09 00
Apr 12 12:10:09 00
Apr 12 12:10:09 00
Apr 12 12:10:09 74
Apr 12 12:10:09 3d
Apr 12 12:10:09 e8
Apr 12 12:10:09 07
Apr 12 12:10:09 fe
Apr 12 12:10:09 ff
Apr 12 12:10:09 ff
Apr 12 12:10:09 66
Apr 12 12:10:09 3d
Apr 12 12:10:09 08
Apr 12 12:10:09 06
Apr 12 12:10:09 75
Apr 12 12:10:09 09
Apr 12 12:10:09 83
Apr 12 12:10:09 3d
Apr 12 12:10:09 98
Apr 12 12:10:09 6a
Apr 12 12:10:09 00
Apr 12 12:10:09 00
Apr 12 12:10:09 00
Apr 12 12:10:09 75
Apr 12 12:10:09 29
Apr 12 12:10:09 lamu
Apr 12 12:10:09 f6
Apr 12 12:10:09 44
Apr 12 12:10:09 24
Apr 12 12:10:09 18
Apr 12 12:10:09 lamu
Apr 12 12:10:09 lamu [71021.610392] ------------[ cut here ]------------
Apr 12 12:10:09 lamu [71021.610395] WARNING: at /build/buildd-linux-2.6_3.2.12-1-amd64-FiPNYf/linux-2.6-3.2.12/debian/build/source_amd64_none/kernel/softirq.c:159 _local_bh_enable_ip.isra.11+0x3d/0x88()
Apr 12 12:10:09 lamu [71021.610398] Hardware name: PowerEdge R410
Apr 12 12:10:09 lamu [71021.610399] Modules linked in: ipt_MASQUERADE iptable_nat nf_nat nf_conntrack_ipv4 nf_defrag_ipv4 ip_vs_rr ip_vs nf_conntrack libcrc32c ip6table_filter ip6_tables iptable_filter ip_tables ebtable_nat ebtables x_tables crc32c drbd lru_cache cn sit tunnel4 tun bridge stp virtio_net virtio_blk virtio_rng rng_core virtio_pci virtio_ring virtio kvm_intel kvm ipmi_devintf ipmi_poweroff ipmi_si ipmi_watchdog ipmi_msghandler netconsole configfs loop option usb_wwan usbserial uas snd_pcm snd_page_alloc snd_timer snd iTCO_wdt iTCO_vendor_support psmouse i7core_edac edac_core processor button soundcore joydev serio_raw pcspkr evdev dcdbas thermal_sys ext3 mbcache jbd dm_mod sr_mod cdrom ses sd_mod usbhid hid crc_t10dif enclosure ata_generic uhci_hcd ata_piix ehci_hcd libata usbcore megaraid_sas scsi_mod usb_common bnx2 [last unloaded: usb_storage]
Apr 12 12:10:09 lamu [71021.610438] Pid: 6997, comm: kvm Not tainted 3.2.0-2-amd64 #1
Apr 12 12:10:09 lamu [71021.610439] Call Trace:
Apr 12 12:10:09 lamu [71021.610440] <IRQ> [<ffffffff81046879>] ? warn_slowpath_common+0x78/0x8c
Apr 12 12:10:09 lamu [71021.610447] [<ffffffff8104bd8a>] ? _local_bh_enable_ip.isra.11+0x3d/0x88
Apr 12 12:10:09 lamu [71021.610454] [<ffffffffa003d748>] ? bnx2_reg_rd_ind+0x31/0x38 [bnx2]
Apr 12 12:10:09 lamu [71021.610460] [<ffffffffa00467d7>] ? bnx2_poll+0x1b7/0x1c4 [bnx2]
Apr 12 12:10:09 lamu [71021.610466] [<ffffffff8129af69>] ? netpoll_poll_dev.part.16+0x9b/0x499
Apr 12 12:10:09 lamu [71021.610475] [<ffffffffa02e331a>] ? br_dev_xmit+0x12e/0x142 [bridge]
Apr 12 12:10:09 lamu [71021.610478] [<ffffffff8129b432>] ? netpoll_send_skb_on_dev+0xcb/0x201
Apr 12 12:10:09 lamu [71021.610483] [<ffffffffa021325c>] ? write_msg+0x98/0xf3 [netconsole]
Apr 12 12:10:09 lamu [71021.610487] [<ffffffff810469c2>] ? __call_console_drivers+0x72/0x83
Apr 12 12:10:09 lamu [71021.610490] [<ffffffff8104708e>] ? console_unlock+0x144/0x1e8
Apr 12 12:10:09 lamu [71021.610493] [<ffffffff810475b1>] ? vprintk+0x396/0x3d9
Apr 12 12:10:09 lamu [71021.610499] [<ffffffffa02e933b>] ? br_nf_forward_finish+0x33/0x95 [bridge]
Apr 12 12:10:09 lamu [71021.610504] [<ffffffffa02e930b>] ? br_nf_forward_finish+0x3/0x95 [bridge]
Apr 12 12:10:09 lamu [71021.610510] [<ffffffff81342a83>] ? printk+0x43/0x48
Apr 12 12:10:09 lamu [71021.610513] [<ffffffff8100fe6a>] ? show_registers+0x1de/0x20a
Apr 12 12:10:09 lamu [71021.610517] [<ffffffff81349f1e>] ? __die+0x8b/0xc8
Apr 12 12:10:09 lamu [71021.610520] [<ffffffff81342253>] ? no_context+0x1d6/0x20e
Apr 12 12:10:09 lamu [71021.610523] [<ffffffff810522ca>] ? __mod_timer+0x139/0x14b
Apr 12 12:10:09 lamu [71021.610526] [<ffffffff8134be99>] ? do_page_fault+0x1a8/0x337
Apr 12 12:10:09 lamu [71021.610531] [<ffffffffa03bef06>] ? ip_vs_conn_put+0x28/0x32 [ip_vs]
Apr 12 12:10:09 lamu [71021.610536] [<ffffffffa03c10e0>] ? ip_vs_out+0x2bd/0x432 [ip_vs]
Apr 12 12:10:09 lamu [71021.610539] [<ffffffff8128beef>] ? dev_hard_start_xmit+0x3fc/0x543
Apr 12 12:10:09 lamu [71021.610542] [<ffffffff813495f5>] ? page_fault+0x25/0x30
Apr 12 12:10:09 lamu [71021.610548] [<ffffffffa02e9308>] ? nf_bridge_update_protocol+0x20/0x20 [bridge]
Apr 12 12:10:09 lamu [71021.610554] [<ffffffffa02e9336>] ? br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 12:10:09 lamu [71021.610559] [<ffffffffa02e9327>] ? br_nf_forward_finish+0x1f/0x95 [bridge]
Apr 12 12:10:09 lamu [71021.610565] [<ffffffffa02e96db>] ? br_parse_ip_options+0x3d/0x19a [bridge]
Apr 12 12:10:09 lamu [71021.610570] [<ffffffffa02e9a67>] ? br_nf_forward_ip+0x1c0/0x1d4 [bridge]
Apr 12 12:10:09 lamu [71021.610573] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 12:10:09 lamu [71021.610578] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:09 lamu [71021.610582] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:09 lamu [71021.610585] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 12:10:09 lamu [71021.610590] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:09 lamu [71021.610595] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:09 lamu [71021.610599] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:09 lamu [71021.610604] [<ffffffffa02e485e>] ? NF_HOOK.constprop.8+0x3c/0x56 [bridge]
Apr 12 12:10:09 lamu [71021.610608] [<ffffffffa02e49f2>] ? br_forward+0x16/0x5a [bridge]
Apr 12 12:10:09 lamu [71021.610613] [<ffffffffa02e551b>] ? br_handle_frame_finish+0x1a1/0x20f [bridge]
Apr 12 12:10:09 lamu [71021.610619] [<ffffffffa02e95ff>] ? br_nf_pre_routing_finish+0x1d0/0x1dd [bridge]
Apr 12 12:10:09 lamu [71021.610624] [<ffffffffa02e8ff0>] ? NF_HOOK_THRESH+0x3b/0x55 [bridge]
Apr 12 12:10:09 lamu [71021.610630] [<ffffffffa02e9f58>] ? br_nf_pre_routing+0x3e8/0x3f5 [bridge]
Apr 12 12:10:09 lamu [71021.610633] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 12:10:09 lamu [71021.610638] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:09 lamu [71021.610641] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 12:10:09 lamu [71021.610646] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:09 lamu [71021.610651] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:09 lamu [71021.610656] [<ffffffffa02e5360>] ? NF_HOOK.constprop.4+0x3c/0x56 [bridge]
Apr 12 12:10:10 lamu [71021.610659] [<ffffffff810135ad>] ? paravirt_read_tsc+0x5/0x8
Apr 12 12:10:10 lamu [71021.610661] [<ffffffff81013622>] ? read_tsc+0x5/0x14
Apr 12 12:10:10 lamu [71021.610666] [<ffffffffa02e573c>] ? br_handle_frame+0x1b3/0x1cb [bridge]
Apr 12 12:10:10 lamu [71021.610671] [<ffffffffa02e5589>] ? br_handle_frame_finish+0x20f/0x20f [bridge]
Apr 12 12:10:10 lamu [71021.610674] [<ffffffff812890cd>] ? __netif_receive_skb+0x324/0x41f
Apr 12 12:10:10 lamu [71021.610677] [<ffffffff81289234>] ? process_backlog+0x6c/0x123
Apr 12 12:10:10 lamu [71021.610681] [<ffffffff8128b11a>] ? net_rx_action+0xa1/0x1af
Apr 12 12:10:10 lamu [71021.610683] [<ffffffff81037013>] ? test_tsk_need_resched+0xa/0x13
Apr 12 12:10:10 lamu [71021.610686] [<ffffffff8104be98>] ? __do_softirq+0xb9/0x177
Apr 12 12:10:10 lamu [71021.610689] [<ffffffff8135026c>] ? call_softirq+0x1c/0x30
Apr 12 12:10:10 lamu [71021.610691] <EOI> [<ffffffff8100f8e5>] ? do_softirq+0x3c/0x7b
Apr 12 12:10:10 lamu [71021.610696] [<ffffffff8128b40a>] ? netif_rx_ni+0x1e/0x27
Apr 12 12:10:10 lamu [71021.610699] [<ffffffffa02f6721>] ? tun_get_user+0x39a/0x3c2 [tun]
Apr 12 12:10:10 lamu [71021.610703] [<ffffffffa02f6a66>] ? tun_chr_poll+0xcd/0xcd [tun]
Apr 12 12:10:10 lamu [71021.610707] [<ffffffffa02f6ac4>] ? tun_chr_aio_write+0x5e/0x79 [tun]
Apr 12 12:10:10 lamu [71021.610710] [<ffffffff810f95d4>] ? do_sync_readv_writev+0x9a/0xd7
Apr 12 12:10:10 lamu [71021.610712] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 12:10:10 lamu [71021.610715] [<ffffffff810f8c56>] ? do_sync_read+0xab/0xe3
Apr 12 12:10:10 lamu [71021.610718] [<ffffffff81061a94>] ? enqueue_hrtimer+0x43/0x6a
Apr 12 12:10:10 lamu [71021.610720] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 12:10:10 lamu [71021.610723] [<ffffffff81162569>] ? security_file_permission+0x16/0x2d
Apr 12 12:10:10 lamu [71021.610726] [<ffffffff810f9838>] ? do_readv_writev+0xaf/0x11c
Apr 12 12:10:10 lamu [71021.610729] [<ffffffff8112abb6>] ? eventfd_ctx_read+0x162/0x174
Apr 12 12:10:10 lamu [71021.610732] [<ffffffff8103f467>] ? try_to_wake_up+0x197/0x197
Apr 12 12:10:10 lamu [71021.610735] [<ffffffff810f9a0d>] ? sys_writev+0x45/0x90
Apr 12 12:10:10 lamu [71021.610738] [<ffffffff8134e012>] ? system_call_fastpath+0x16/0x1b
Apr 12 12:10:10 lamu [71021.610740] ---[ end trace 8375ccada030e5cf ]---
Apr 12 12:10:10 lamu [71022.752807] 01
Apr 12 12:10:10 49
Apr 12 12:10:10 8b
Apr 12 12:10:10 6c
Apr 12 12:10:10 24
Apr 12 12:10:10 08
Apr 12 12:10:10 74
Apr 12 12:10:10 12
Apr 12 12:10:10 8a
Apr 12 12:10:10 43
Apr 12 12:10:10 7d
Apr 12 12:10:10 83
Apr 12 12:10:10 e0
Apr 12 12:10:10 f8
Apr 12 12:10:10 83
Apr 12 12:10:10 c8
Apr 12 12:10:10 lamu
Apr 12 12:10:10 lamu [71022.764300] RIP
Apr 12 12:10:10 lamu [<ffffffffa02e9336>] br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 12:10:10 lamu [71022.778567] RSP <ffff88042fc03b18>
Apr 12 12:10:10 lamu [71022.785531] CR2: 0000000000000018
Apr 12 12:10:10 lamu [71022.792904] ---[ end trace 8375ccada030e5d0 ]---
Apr 12 12:10:10 lamu [71022.802344] Kernel panic - not syncing: Fatal exception in interrupt
Apr 12 12:10:10 lamu [71022.815396] Pid: 6997, comm: kvm Tainted: G D W 3.2.0-2-amd64 #1
Apr 12 12:10:10 lamu [71022.829110] Call Trace:
Apr 12 12:10:10 lamu [71022.834258] <IRQ>
Apr 12 12:10:10 lamu [<ffffffff81342930>] ? panic+0x95/0x1a5
Apr 12 12:10:10 lamu [71022.845768] [<ffffffff81349e86>] ? oops_end+0xa9/0xb6
Apr 12 12:10:10 lamu [71022.856213] [<ffffffff8134227c>] ? no_context+0x1ff/0x20e
Apr 12 12:10:10 lamu [71022.867373] [<ffffffff810522ca>] ? __mod_timer+0x139/0x14b
Apr 12 12:10:10 lamu [71022.878693] [<ffffffff8134be99>] ? do_page_fault+0x1a8/0x337
Apr 12 12:10:10 lamu [71022.890360] [<ffffffffa03bef06>] ? ip_vs_conn_put+0x28/0x32 [ip_vs]
Apr 12 12:10:10 lamu [71022.903203] [<ffffffffa03c10e0>] ? ip_vs_out+0x2bd/0x432 [ip_vs]
Apr 12 12:10:10 lamu [71022.915544] [<ffffffff8128beef>] ? dev_hard_start_xmit+0x3fc/0x543
Apr 12 12:10:10 lamu [71022.928295] [<ffffffff813495f5>] ? page_fault+0x25/0x30
Apr 12 12:10:10 lamu [71022.939318] [<ffffffffa02e9308>] ? nf_bridge_update_protocol+0x20/0x20 [bridge]
Apr 12 12:10:10 lamu [71022.954340] [<ffffffffa02e9336>] ? br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 12:10:10 lamu [71022.968527] [<ffffffffa02e9327>] ? br_nf_forward_finish+0x1f/0x95 [bridge]
Apr 12 12:10:10 lamu [71022.982717] [<ffffffffa02e96db>] ? br_parse_ip_options+0x3d/0x19a [bridge]
Apr 12 12:10:10 lamu [71022.996993] [<ffffffffa02e9a67>] ? br_nf_forward_ip+0x1c0/0x1d4 [bridge]
Apr 12 12:10:10 lamu [71023.010841] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 12:10:10 lamu [71023.021812] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:10 lamu [71023.034570] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:10 lamu [71023.047401] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 12:10:10 lamu [71023.058757] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:10 lamu [71023.071501] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:10 lamu [71023.085667] [<ffffffffa02e4918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 12:10:10 lamu [71023.098483] [<ffffffffa02e485e>] ? NF_HOOK.constprop.8+0x3c/0x56 [bridge]
Apr 12 12:10:10 lamu [71023.112500] [<ffffffffa02e49f2>] ? br_forward+0x16/0x5a [bridge]
Apr 12 12:10:10 lamu [71023.124825] [<ffffffffa02e551b>] ? br_handle_frame_finish+0x1a1/0x20f [bridge]
Apr 12 12:10:10 lamu [71023.139763] [<ffffffffa02e95ff>] ? br_nf_pre_routing_finish+0x1d0/0x1dd [bridge]
Apr 12 12:10:10 lamu [71023.154965] [<ffffffffa02e8ff0>] ? NF_HOOK_THRESH+0x3b/0x55 [bridge]
Apr 12 12:10:10 lamu [71023.168151] [<ffffffffa02e9f58>] ? br_nf_pre_routing+0x3e8/0x3f5 [bridge]
Apr 12 12:10:10 lamu [71023.182191] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 12:10:10 lamu [71023.193200] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:10 lamu [71023.207169] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 12:10:10 lamu [71023.218614] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:10 lamu [71023.232581] [<ffffffffa02e537a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 12:10:10 lamu [71023.246548] [<ffffffffa02e5360>] ? NF_HOOK.constprop.4+0x3c/0x56 [bridge]
Apr 12 12:10:10 lamu [71023.260552] [<ffffffff810135ad>] ? paravirt_read_tsc+0x5/0x8
Apr 12 12:10:10 lamu [71023.272274] [<ffffffff81013622>] ? read_tsc+0x5/0x14
Apr 12 12:10:10 lamu [71023.282710] [<ffffffffa02e573c>] ? br_handle_frame+0x1b3/0x1cb [bridge]
Apr 12 12:10:10 lamu [71023.296308] [<ffffffffa02e5589>] ? br_handle_frame_finish+0x20f/0x20f [bridge]
Apr 12 12:10:10 lamu [71023.296338] block drbd4: PingAck did not arrive in time.
Apr 12 12:10:10 lamu [71023.296347] block drbd4: peer( Secondary -> Unknown ) conn( Connected -> NetworkFailure ) pdsk( UpToDate -> DUnknown )
Apr 12 12:10:10 lamu [71023.343474] [<ffffffff812890cd>] ? __netif_receive_skb+0x324/0x41f
Apr 12 12:10:10 lamu [71023.356221] [<ffffffff81289234>] ? process_backlog+0x6c/0x123
Apr 12 12:10:10 lamu [71023.368057] [<ffffffff8128b11a>] ? net_rx_action+0xa1/0x1af
Apr 12 12:10:10 lamu [71023.379483] [<ffffffff81037013>] ? test_tsk_need_resched+0xa/0x13
Apr 12 12:10:10 lamu [71023.391998] [<ffffffff8104be98>] ? __do_softirq+0xb9/0x177
Apr 12 12:10:10 lamu [71023.403332] [<ffffffff8135026c>] ? call_softirq+0x1c/0x30
Apr 12 12:10:10 lamu [71023.414444] <EOI>
Apr 12 12:10:10 lamu [<ffffffff8100f8e5>] ? do_softirq+0x3c/0x7b
Apr 12 12:10:11 lamu [71023.426647] [<ffffffff8128b40a>] ? netif_rx_ni+0x1e/0x27
Apr 12 12:10:11 lamu [71023.437640] [<ffffffffa02f6721>] ? tun_get_user+0x39a/0x3c2 [tun]
Apr 12 12:10:11 lamu [71023.450264] [<ffffffffa02f6a66>] ? tun_chr_poll+0xcd/0xcd [tun]
Apr 12 12:10:11 lamu [71023.462501] [<ffffffffa02f6ac4>] ? tun_chr_aio_write+0x5e/0x79 [tun]
Apr 12 12:10:11 lamu [71023.475526] [<ffffffff810f95d4>] ? do_sync_readv_writev+0x9a/0xd7
Apr 12 12:10:11 lamu [71023.488074] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 12:10:11 lamu [71023.499357] [<ffffffff810f8c56>] ? do_sync_read+0xab/0xe3
Apr 12 12:10:11 lamu [71023.510429] [<ffffffff81061a94>] ? enqueue_hrtimer+0x43/0x6a
Apr 12 12:10:11 lamu [71023.522066] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 12:10:11 lamu [71023.533310] [<ffffffff81162569>] ? security_file_permission+0x16/0x2d
Apr 12 12:10:11 lamu [71023.546463] [<ffffffff810f9838>] ? do_readv_writev+0xaf/0x11c
Apr 12 12:10:11 lamu [71023.558352] [<ffffffff8112abb6>] ? eventfd_ctx_read+0x162/0x174
Apr 12 12:10:11 lamu [71023.570467] [<ffffffff8103f467>] ? try_to_wake_up+0x197/0x197
Apr 12 12:10:11 lamu [71023.582316] [<ffffffff810f9a0d>] ? sys_writev+0x45/0x90
Apr 12 12:10:11 lamu [71023.593177] [<ffffffff8134e012>] ? system_call_fastpath+0x16/0x1b
[-- Attachment #3: BUG2.txt --]
[-- Type: text/plain, Size: 17365 bytes --]
Apr 12 13:22:05 lamu [ 4116.902924] BUG: unable to handle kernel
Apr 12 13:22:05 NULL pointer dereference
Apr 12 13:22:05 lamu at 0000000000000018
Apr 12 13:22:05 lamu [ 4116.918581] IP:
Apr 12 13:22:05 lamu [<ffffffffa02d2336>] br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 13:22:05 lamu [ 4116.932666] PGD 0
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4116.936681] Oops: 0000 [#1]
Apr 12 13:22:05 SMP
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4116.943136] CPU 0
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4116.946792] Modules linked in:
Apr 12 13:22:05 lamu option
Apr 12 13:22:05 lamu usb_wwan
Apr 12 13:22:05 lamu usbserial
Apr 12 13:22:05 lamu usb_storage
Apr 12 13:22:05 lamu uas
Apr 12 13:22:05 lamu ipt_MASQUERADE
Apr 12 13:22:05 lamu iptable_nat
Apr 12 13:22:05 lamu nf_nat
Apr 12 13:22:05 lamu nf_conntrack_ipv4
Apr 12 13:22:05 lamu nf_defrag_ipv4
Apr 12 13:22:05 lamu ip_vs_rr
Apr 12 13:22:05 lamu ip_vs
Apr 12 13:22:05 lamu nf_conntrack
Apr 12 13:22:05 lamu libcrc32c
Apr 12 13:22:05 lamu ip6table_filter
Apr 12 13:22:05 lamu ip6_tables
Apr 12 13:22:05 lamu iptable_filter
Apr 12 13:22:05 lamu ip_tables
Apr 12 13:22:05 lamu ebtable_nat
Apr 12 13:22:05 lamu ebtables
Apr 12 13:22:05 lamu x_tables
Apr 12 13:22:05 lamu crc32c
Apr 12 13:22:05 lamu drbd
Apr 12 13:22:05 lamu lru_cache
Apr 12 13:22:05 lamu cn
Apr 12 13:22:05 lamu sit
Apr 12 13:22:05 lamu tunnel4
Apr 12 13:22:05 lamu tun
Apr 12 13:22:05 lamu bridge
Apr 12 13:22:05 lamu stp
Apr 12 13:22:05 lamu virtio_net
Apr 12 13:22:05 lamu virtio_blk
Apr 12 13:22:05 lamu virtio_rng
Apr 12 13:22:05 lamu rng_core
Apr 12 13:22:05 lamu virtio_pci
Apr 12 13:22:05 lamu virtio_ring
Apr 12 13:22:05 lamu virtio
Apr 12 13:22:05 lamu kvm_intel
Apr 12 13:22:05 lamu kvm
Apr 12 13:22:05 lamu ipmi_devintf
Apr 12 13:22:05 lamu ipmi_poweroff
Apr 12 13:22:05 lamu ipmi_si
Apr 12 13:22:05 lamu ipmi_watchdog
Apr 12 13:22:05 lamu ipmi_msghandler
Apr 12 13:22:05 lamu netconsole
Apr 12 13:22:05 lamu configfs
Apr 12 13:22:05 lamu loop
Apr 12 13:22:05 lamu snd_pcm
Apr 12 13:22:05 lamu snd_page_alloc
Apr 12 13:22:05 lamu iTCO_wdt
Apr 12 13:22:05 lamu snd_timer
Apr 12 13:22:05 lamu snd
Apr 12 13:22:05 lamu processor
Apr 12 13:22:05 lamu button
Apr 12 13:22:05 lamu iTCO_vendor_support
Apr 12 13:22:05 lamu joydev
Apr 12 13:22:05 lamu i7core_edac
Apr 12 13:22:05 lamu edac_core
Apr 12 13:22:05 lamu soundcore
Apr 12 13:22:05 lamu pcspkr
Apr 12 13:22:05 lamu psmouse
Apr 12 13:22:05 lamu serio_raw
Apr 12 13:22:05 lamu evdev
Apr 12 13:22:05 lamu thermal_sys
Apr 12 13:22:05 lamu dcdbas
Apr 12 13:22:05 lamu ext3
Apr 12 13:22:05 lamu mbcache
Apr 12 13:22:05 lamu jbd
Apr 12 13:22:05 lamu dm_mod
Apr 12 13:22:05 lamu sr_mod
Apr 12 13:22:05 lamu cdrom
Apr 12 13:22:05 lamu sd_mod
Apr 12 13:22:05 lamu ses
Apr 12 13:22:05 lamu usbhid
Apr 12 13:22:05 lamu hid
Apr 12 13:22:05 lamu enclosure
Apr 12 13:22:05 lamu crc_t10dif
Apr 12 13:22:05 lamu ata_generic
Apr 12 13:22:05 lamu ata_piix
Apr 12 13:22:05 lamu uhci_hcd
Apr 12 13:22:05 lamu libata
Apr 12 13:22:05 lamu ehci_hcd
Apr 12 13:22:05 lamu megaraid_sas
Apr 12 13:22:05 lamu usbcore
Apr 12 13:22:05 lamu scsi_mod
Apr 12 13:22:05 lamu usb_common
Apr 12 13:22:05 lamu bnx2
Apr 12 13:22:05 lamu [last unloaded: scsi_wait_scan]
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4117.098774]
Apr 12 13:22:05 lamu [ 4117.101737] Pid: 5417, comm: kvm Not tainted 3.2.0-2-amd64 #1
Apr 12 13:22:05 lamu Dell Inc. PowerEdge R410
Apr 12 13:22:05 lamu /0N051F
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4117.118781] RIP: 0010:[<ffffffffa02d2336>]
Apr 12 13:22:05 lamu [<ffffffffa02d2336>] br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 13:22:05 lamu [ 4117.137734] RSP: 0018:ffff88042fc03b18 EFLAGS: 00010293
Apr 12 13:22:05 lamu [ 4117.148342] RAX: 0000000000000000 RBX: ffff88041a59cc80 RCX: 0000000000000006
Apr 12 13:22:05 lamu [ 4117.162591] RDX: ffffffffa02d2308 RSI: 00000001000ecc40 RDI: ffff88041a59cc80
Apr 12 13:22:05 lamu [ 4117.176840] RBP: ffff880424574000 R08: 0000000000000000 R09: ffff88042fc03ad0
Apr 12 13:22:05 lamu [ 4117.191088] R10: ffffffff8165aac0 R11: ffffffff8165aac0 R12: 0000000000000000
Apr 12 13:22:05 lamu [ 4117.205338] R13: ffff880225b90002 R14: ffff88042543c8c0 R15: ffff880225b90000
Apr 12 13:22:05 lamu [ 4117.219589] FS: 00007f673f979900(0000) GS:ffff88042fc00000(0000) knlGS:0000000000000000
Apr 12 13:22:05 lamu [ 4117.235765] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Apr 12 13:22:05 lamu [ 4117.247239] CR2: 0000000000000018 CR3: 00000001be517000 CR4: 00000000000026e0
Apr 12 13:22:05 lamu [ 4117.261488] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
Apr 12 13:22:05 lamu [ 4117.275738] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Apr 12 13:22:05 lamu [ 4117.289988] Process kvm (pid: 5417, threadinfo ffff8801be51e000, task ffff880226aea240)
Apr 12 13:22:05 lamu [ 4117.305985] Stack:
Apr 12 13:22:05 lamu [ 4117.310002] ffffffff80000000
Apr 12 13:22:05 lamu ffffffffa02d26db
Apr 12 13:22:05 lamu ffff88041a59cc80
Apr 12 13:22:05 lamu ffff880424574000
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4117.324838] ffff880424411000
Apr 12 13:22:05 lamu ffffffffa02d2a67
Apr 12 13:22:05 lamu ffff880480000000
Apr 12 13:22:05 lamu 0000000200000000
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4117.339670] ffff88041a59cc80
Apr 12 13:22:05 lamu ffffffffa02d8cd0
Apr 12 13:22:05 lamu ffffffff81691190
Apr 12 13:22:05 lamu 0000000000000002
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4117.354501] Call Trace:
Apr 12 13:22:05 lamu [ 4117.359386] <IRQ>
Apr 12 13:22:05 lamu
Apr 12 13:22:05 lamu [ 4117.363594] [<ffffffffa02d26db>] ? br_parse_ip_options+0x3d/0x19a [bridge]
Apr 12 13:22:05 lamu [ 4117.377501] [<ffffffffa02d2a67>] ? br_nf_forward_ip+0x1c0/0x1d4 [bridge]
Apr 12 13:22:05 lamu [ 4117.391063] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 13:22:05 lamu [ 4117.401673] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:05 lamu [ 4117.414191] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:05 lamu [ 4117.426708] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 13:22:05 lamu [ 4117.437839] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:05 lamu [ 4117.450358] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:05 lamu [ 4117.464092] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:05 lamu [ 4117.476612] [<ffffffffa02cd85e>] ? NF_HOOK.constprop.8+0x3c/0x56 [bridge]
Apr 12 13:22:05 lamu [ 4117.490345] [<ffffffffa02cd9f2>] ? br_forward+0x16/0x5a [bridge]
Apr 12 13:22:05 lamu [ 4117.502517] [<ffffffffa02ce51b>] ? br_handle_frame_finish+0x1a1/0x20f [bridge]
Apr 12 13:22:05 lamu [ 4117.517132] [<ffffffffa02d25ff>] ? br_nf_pre_routing_finish+0x1d0/0x1dd [bridge]
Apr 12 13:22:05 lamu [ 4117.532096] [<ffffffffa02d1ff0>] ? NF_HOOK_THRESH+0x3b/0x55 [bridge]
Apr 12 13:22:05 lamu [ 4117.544963] [<ffffffffa02d2f58>] ? br_nf_pre_routing+0x3e8/0x3f5 [bridge]
Apr 12 13:22:05 lamu [ 4117.558695] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 13:22:05 lamu [ 4117.569309] [<ffffffff8128affc>] ? napi_gro_receive+0x1d/0x2b
Apr 12 13:22:05 lamu [ 4117.580957] [<ffffffff8128aba6>] ? napi_skb_finish+0x1c/0x31
Apr 12 13:22:05 lamu [ 4117.592436] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:05 lamu [ 4117.606167] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 13:22:05 lamu [ 4117.617298] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:05 lamu [ 4117.631033] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:05 lamu [ 4117.644766] [<ffffffffa02ce360>] ? NF_HOOK.constprop.4+0x3c/0x56 [bridge]
Apr 12 13:22:05 lamu [ 4117.658498] [<ffffffff8128b06a>] ? napi_complete+0x28/0x37
Apr 12 13:22:05 lamu [ 4117.669629] [<ffffffffa02ce73c>] ? br_handle_frame+0x1b3/0x1cb [bridge]
Apr 12 13:22:05 lamu [ 4117.683016] [<ffffffffa02ce589>] ? br_handle_frame_finish+0x20f/0x20f [bridge]
Apr 12 13:22:05 lamu [ 4117.697630] [<ffffffff812890cd>] ? __netif_receive_skb+0x324/0x41f
Apr 12 13:22:05 lamu [ 4117.710146] [<ffffffff81289234>] ? process_backlog+0x6c/0x123
Apr 12 13:22:06 lamu [ 4117.721797] [<ffffffff8128b11a>] ? net_rx_action+0xa1/0x1af
Apr 12 13:22:06 lamu [ 4117.733102] [<ffffffff81037013>] ? test_tsk_need_resched+0xa/0x13
Apr 12 13:22:06 lamu [ 4117.745446] [<ffffffff8104be98>] ? __do_softirq+0xb9/0x177
Apr 12 13:22:06 lamu [ 4117.756579] [<ffffffff8135026c>] ? call_softirq+0x1c/0x30
Apr 12 13:22:06 lamu [ 4117.767535] <EOI>
Apr 12 13:22:06 lamu
Apr 12 13:22:06 lamu [ 4117.771741] [<ffffffff8100f8e5>] ? do_softirq+0x3c/0x7b
Apr 12 13:22:06 lamu [ 4117.782350] [<ffffffff8128b40a>] ? netif_rx_ni+0x1e/0x27
Apr 12 13:22:06 lamu [ 4117.793134] [<ffffffffa025b721>] ? tun_get_user+0x39a/0x3c2 [tun]
Apr 12 13:22:06 lamu [ 4117.805477] [<ffffffffa025ba66>] ? tun_chr_poll+0xcd/0xcd [tun]
Apr 12 13:22:06 lamu [ 4117.817475] [<ffffffffa025bac4>] ? tun_chr_aio_write+0x5e/0x79 [tun]
Apr 12 13:22:06 lamu [ 4117.830342] [<ffffffff810f95d4>] ? do_sync_readv_writev+0x9a/0xd7
Apr 12 13:22:06 lamu [ 4117.842686] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 13:22:06 lamu [ 4117.853817] [<ffffffff810f8c56>] ? do_sync_read+0xab/0xe3
Apr 12 13:22:06 lamu [ 4117.864772] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 13:22:06 lamu [ 4117.875906] [<ffffffff81162569>] ? security_file_permission+0x16/0x2d
Apr 12 13:22:06 lamu [ 4117.888942] [<ffffffff810f9838>] ? do_readv_writev+0xaf/0x11c
Apr 12 13:22:06 lamu [ 4117.900596] [<ffffffff8112abb6>] ? eventfd_ctx_read+0x162/0x174
Apr 12 13:22:06 lamu [ 4117.912597] [<ffffffff8103f467>] ? try_to_wake_up+0x197/0x197
Apr 12 13:22:06 lamu [ 4117.924248] [<ffffffff810f9a0d>] ? sys_writev+0x45/0x90
Apr 12 13:22:06 lamu [ 4117.934859] [<ffffffff8134e012>] ? system_call_fastpath+0x16/0x1b
Apr 12 13:22:06 lamu [ 4117.947201] Code:
Apr 12 13:22:06 53
Apr 12 13:22:06 48
Apr 12 13:22:06 89
Apr 12 13:22:06 fb
Apr 12 13:22:06 48
Apr 12 13:22:06 83
Apr 12 13:22:06 ec
Apr 12 13:22:06 10
Apr 12 13:22:06 66
Apr 12 13:22:06 81
Apr 12 13:22:06 7f
Apr 12 13:22:06 7e
Apr 12 13:22:06 08
Apr 12 13:22:06 06
Apr 12 13:22:06 4c
Apr 12 13:22:06 8b
Apr 12 13:22:06 a7
Apr 12 13:22:06 98
Apr 12 13:22:06 00
Apr 12 13:22:06 00
Apr 12 13:22:06 00
Apr 12 13:22:06 74
Apr 12 13:22:06 3d
Apr 12 13:22:06 e8
Apr 12 13:22:06 07
Apr 12 13:22:06 fe
Apr 12 13:22:06 ff
Apr 12 13:22:06 ff
Apr 12 13:22:06 66
Apr 12 13:22:06 3d
Apr 12 13:22:06 08
Apr 12 13:22:06 06
Apr 12 13:22:06 75
Apr 12 13:22:06 09
Apr 12 13:22:06 83
Apr 12 13:22:06 3d
Apr 12 13:22:06 98
Apr 12 13:22:06 6a
Apr 12 13:22:06 00
Apr 12 13:22:06 00
Apr 12 13:22:06 00
Apr 12 13:22:06 75
Apr 12 13:22:06 29
Apr 12 13:22:06 lamu
Apr 12 13:22:06 f6
Apr 12 13:22:06 44
Apr 12 13:22:06 24
Apr 12 13:22:06 18
Apr 12 13:22:06 01
Apr 12 13:22:06 49
Apr 12 13:22:06 8b
Apr 12 13:22:06 6c
Apr 12 13:22:06 24
Apr 12 13:22:06 08
Apr 12 13:22:06 74
Apr 12 13:22:06 12
Apr 12 13:22:06 8a
Apr 12 13:22:06 43
Apr 12 13:22:06 7d
Apr 12 13:22:06 83
Apr 12 13:22:06 e0
Apr 12 13:22:06 f8
Apr 12 13:22:06 83
Apr 12 13:22:06 c8
Apr 12 13:22:06 lamu
Apr 12 13:22:06 lamu [ 4117.985837] RIP
Apr 12 13:22:06 lamu [<ffffffffa02d2336>] br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 13:22:06 lamu [ 4118.000102] RSP <ffff88042fc03b18>
Apr 12 13:22:06 lamu [ 4118.007067] CR2: 0000000000000018
Apr 12 13:22:06 lamu [ 4118.014273] ---[ end trace c19a5656967502d9 ]---
Apr 12 13:22:06 lamu [ 4118.023651] Kernel panic - not syncing: Fatal exception in interrupt
Apr 12 13:22:06 lamu [ 4118.036551] Pid: 5417, comm: kvm Tainted: G D 3.2.0-2-amd64 #1
Apr 12 13:22:06 lamu [ 4118.050125] Call Trace:
Apr 12 13:22:06 lamu [ 4118.055141] <IRQ>
Apr 12 13:22:06 lamu [<ffffffff81342930>] ? panic+0x95/0x1a5
Apr 12 13:22:06 lamu [ 4118.066812] [<ffffffff81349e86>] ? oops_end+0xa9/0xb6
Apr 12 13:22:06 lamu [ 4118.077374] [<ffffffff8134227c>] ? no_context+0x1ff/0x20e
Apr 12 13:22:06 lamu [ 4118.088585] [<ffffffff810e9cd8>] ? virt_to_slab+0x6/0x16
Apr 12 13:22:06 lamu [ 4118.099505] [<ffffffff8134be99>] ? do_page_fault+0x1a8/0x337
Apr 12 13:22:06 lamu [ 4118.111234] [<ffffffffa03b4f06>] ? ip_vs_conn_put+0x28/0x32 [ip_vs]
Apr 12 13:22:06 lamu [ 4118.124097] [<ffffffffa03b70e0>] ? ip_vs_out+0x2bd/0x432 [ip_vs]
Apr 12 13:22:06 lamu [ 4118.136534] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 13:22:06 lamu [ 4118.147846] [<ffffffff813495f5>] ? page_fault+0x25/0x30
Apr 12 13:22:06 lamu [ 4118.158871] [<ffffffffa02d2308>] ? nf_bridge_update_protocol+0x20/0x20 [bridge]
Apr 12 13:22:06 lamu [ 4118.173852] [<ffffffffa02d2336>] ? br_nf_forward_finish+0x2e/0x95 [bridge]
Apr 12 13:22:06 lamu [ 4118.187919] [<ffffffffa02d2327>] ? br_nf_forward_finish+0x1f/0x95 [bridge]
Apr 12 13:22:06 lamu [ 4118.202024] [<ffffffffa02d26db>] ? br_parse_ip_options+0x3d/0x19a [bridge]
Apr 12 13:22:06 lamu [ 4118.216187] [<ffffffffa02d2a67>] ? br_nf_forward_ip+0x1c0/0x1d4 [bridge]
Apr 12 13:22:06 lamu [ 4118.230137] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 13:22:06 lamu [ 4118.241005] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:06 lamu [ 4118.253701] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:06 lamu [ 4118.266471] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 13:22:06 lamu [ 4118.277931] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:06 lamu [ 4118.290618] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:06 lamu [ 4118.304695] [<ffffffffa02cd918>] ? __br_deliver+0xa0/0xa0 [bridge]
Apr 12 13:22:06 lamu [ 4118.317523] [<ffffffffa02cd85e>] ? NF_HOOK.constprop.8+0x3c/0x56 [bridge]
Apr 12 13:22:06 lamu [ 4118.331508] [<ffffffffa02cd9f2>] ? br_forward+0x16/0x5a [bridge]
Apr 12 13:22:06 lamu [ 4118.343911] [<ffffffffa02ce51b>] ? br_handle_frame_finish+0x1a1/0x20f [bridge]
Apr 12 13:22:06 lamu [ 4118.358880] [<ffffffffa02d25ff>] ? br_nf_pre_routing_finish+0x1d0/0x1dd [bridge]
Apr 12 13:22:06 lamu [ 4118.374318] [<ffffffffa02d1ff0>] ? NF_HOOK_THRESH+0x3b/0x55 [bridge]
Apr 12 13:22:06 lamu [ 4118.387534] [<ffffffffa02d2f58>] ? br_nf_pre_routing+0x3e8/0x3f5 [bridge]
Apr 12 13:22:06 lamu [ 4118.401597] [<ffffffff812abe4d>] ? nf_iterate+0x41/0x77
Apr 12 13:22:06 lamu [ 4118.412543] [<ffffffff8128affc>] ? napi_gro_receive+0x1d/0x2b
Apr 12 13:22:06 lamu [ 4118.424529] [<ffffffff8128aba6>] ? napi_skb_finish+0x1c/0x31
Apr 12 13:22:06 lamu [ 4118.436261] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:06 lamu [ 4118.450326] [<ffffffff812abeeb>] ? nf_hook_slow+0x68/0x101
Apr 12 13:22:06 lamu [ 4118.461719] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:06 lamu [ 4118.475801] [<ffffffffa02ce37a>] ? NF_HOOK.constprop.4+0x56/0x56 [bridge]
Apr 12 13:22:06 lamu [ 4118.489866] [<ffffffffa02ce360>] ? NF_HOOK.constprop.4+0x3c/0x56 [bridge]
Apr 12 13:22:06 lamu [ 4118.503947] [<ffffffff8128b06a>] ? napi_complete+0x28/0x37
Apr 12 13:22:06 lamu [ 4118.515485] [<ffffffffa02ce73c>] ? br_handle_frame+0x1b3/0x1cb [bridge]
Apr 12 13:22:06 lamu [ 4118.529269] [<ffffffffa02ce589>] ? br_handle_frame_finish+0x20f/0x20f [bridge]
Apr 12 13:22:06 lamu [ 4118.544220] [<ffffffff812890cd>] ? __netif_receive_skb+0x324/0x41f
Apr 12 13:22:06 lamu [ 4118.557192] [<ffffffff81289234>] ? process_backlog+0x6c/0x123
Apr 12 13:22:06 lamu [ 4118.569098] [<ffffffff8128b11a>] ? net_rx_action+0xa1/0x1af
Apr 12 13:22:06 lamu [ 4118.580632] [<ffffffff81037013>] ? test_tsk_need_resched+0xa/0x13
Apr 12 13:22:06 lamu [ 4118.593292] [<ffffffff8104be98>] ? __do_softirq+0xb9/0x177
Apr 12 13:22:06 lamu [ 4118.604759] [<ffffffff8135026c>] ? call_softirq+0x1c/0x30
Apr 12 13:22:06 lamu [ 4118.616040] <EOI>
Apr 12 13:22:06 lamu [<ffffffff8100f8e5>] ? do_softirq+0x3c/0x7b
Apr 12 13:22:06 lamu [ 4118.628382] [<ffffffff8128b40a>] ? netif_rx_ni+0x1e/0x27
Apr 12 13:22:06 lamu [ 4118.639571] [<ffffffffa025b721>] ? tun_get_user+0x39a/0x3c2 [tun]
Apr 12 13:22:06 lamu [ 4118.652220] [<ffffffffa025ba66>] ? tun_chr_poll+0xcd/0xcd [tun]
Apr 12 13:22:06 lamu [ 4118.664445] [<ffffffffa025bac4>] ? tun_chr_aio_write+0x5e/0x79 [tun]
Apr 12 13:22:06 lamu [ 4118.677553] [<ffffffff810f95d4>] ? do_sync_readv_writev+0x9a/0xd7
Apr 12 13:22:06 lamu [ 4118.690220] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 13:22:06 lamu [ 4118.701591] [<ffffffff810f8c56>] ? do_sync_read+0xab/0xe3
Apr 12 13:22:06 lamu [ 4118.712765] [<ffffffff8103642f>] ? should_resched+0x5/0x23
Apr 12 13:22:07 lamu [ 4118.724209] [<ffffffff81162569>] ? security_file_permission+0x16/0x2d
Apr 12 13:22:07 lamu [ 4118.737632] [<ffffffff810f9838>] ? do_readv_writev+0xaf/0x11c
Apr 12 13:22:07 lamu [ 4118.749500] [<ffffffff8112abb6>] ? eventfd_ctx_read+0x162/0x174
Apr 12 13:22:07 lamu [ 4118.761817] [<ffffffff8103f467>] ? try_to_wake_up+0x197/0x197
Apr 12 13:22:07 lamu [ 4118.773669] [<ffffffff810f9a0d>] ? sys_writev+0x45/0x90
Apr 12 13:22:07 lamu [ 4118.784671] [<ffffffff8134e012>] ? system_call_fastpath+0x16/0x1b
^ permalink raw reply
* Re: Kernel panic with bridge networking
From: Eric Dumazet @ 2012-04-12 12:52 UTC (permalink / raw)
To: Massimo Cetra; +Cc: netdev, Peter Huang (Peng)
In-Reply-To: <4F86CACB.8010907@navynet.it>
On Thu, 2012-04-12 at 14:30 +0200, Massimo Cetra wrote:
> Hello,
>
> i am experiencing a panic whose logs are attached (grabbed with netconsole).
>
> They look quite similar to what has been described here
> http://www.spinics.net/lists/linux-net/msg17689.html
>
> The patch proposed as the solution (commit
> 6b1e960fdbd75dcd9bcc3ba5ff8898ff1ad30b6e) seems to be applied (even with
> small differences) but the problem persists.
>
> The kernel is a debian linux-image-3.2.0-2-amd64 version 3.2.12-1
>
> Any hint ?
> I have checked the changelog of 3.2.13 and 3.2.14 and it doesn't seems
> to be any commit regarding such problems.
>
> Massimo Cetra
>
> P.S.1: Please CC me as i'm not subscribed.
> P.S.2: this bug has been submitted to debian as well
> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668511
>
Known issue, and we are waiting from a fix from Peter.
https://lkml.org/lkml/2012/3/31/17
Peter, any progress on your side ?
Thanks
^ permalink raw reply
* Re: [PATCH] net: smsc911x: fix RX FIFO fastforwarding when dropping packets
From: Will Deacon @ 2012-04-12 12:53 UTC (permalink / raw)
To: Eric Dumazet; +Cc: netdev@vger.kernel.org, Steve Glendinning
In-Reply-To: <1334222448.5300.6046.camel@edumazet-glaptop>
Hi Eric,
Thanks for taking a look.
On Thu, Apr 12, 2012 at 10:20:48AM +0100, Eric Dumazet wrote:
> On Thu, 2012-04-12 at 10:07 +0100, Will Deacon wrote:
> > diff --git a/drivers/net/ethernet/smsc/smsc911x.c b/drivers/net/ethernet/smsc/smsc911x.c
> > index 4a69710..b5599bc 100644
> > --- a/drivers/net/ethernet/smsc/smsc911x.c
> > +++ b/drivers/net/ethernet/smsc/smsc911x.c
> > @@ -1228,7 +1228,7 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
> > "Discarding packet with error bit set");
> > /* Packet has an error, discard it and continue with
> > * the next */
> > - smsc911x_rx_fastforward(pdata, pktwords);
> > + smsc911x_rx_fastforward(pdata, pktlength);
> > dev->stats.rx_dropped++;
> > continue;
> > }
[...]
> Hum, looking at this driver, I see wrong code in lines 1246/1247
>
> skb->data = skb->head;
> skb_reset_tail_pointer(skb);
>
> I suspect its hiding a buffer overflow bug or something.
Yes, you're right.
> netdev_alloc_skb() reserved NET_SKB_PAD bytes. A driver should not
> un-reserve this headroom, or some networking setups can be very slow.
>
> So
>
> pdata->ops->rx_readfifo(pdata,
> (unsigned int *)skb->head, pktwords);
>
> also should be fixed to use skb->data instead.
Right, this seems to do the trick (and can replace my original patch by
actually passing in the number of words to the fastforward function). I'm
not sure whether the skb_trim is really required, but it makes the data
format slightly clearer.
It would be nice to get some input from Steve, but his email address seems
to be bouncing at the moment.
Will
diff --git a/drivers/net/ethernet/smsc/smsc911x.c b/drivers/net/ethernet/smsc/smsc911x.c
index 4a69710..3f43c24 100644
--- a/drivers/net/ethernet/smsc/smsc911x.c
+++ b/drivers/net/ethernet/smsc/smsc911x.c
@@ -1166,10 +1166,8 @@ smsc911x_rx_counterrors(struct net_device *dev, unsigned int rxstat)
/* Quickly dumps bad packets */
static void
-smsc911x_rx_fastforward(struct smsc911x_data *pdata, unsigned int pktbytes)
+smsc911x_rx_fastforward(struct smsc911x_data *pdata, unsigned int pktwords)
{
- unsigned int pktwords = (pktbytes + NET_IP_ALIGN + 3) >> 2;
-
if (likely(pktwords >= 4)) {
unsigned int timeout = 500;
unsigned int val;
@@ -1233,7 +1231,7 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
continue;
}
- skb = netdev_alloc_skb(dev, pktlength + NET_IP_ALIGN);
+ skb = netdev_alloc_skb(dev, pktwords << 2);
if (unlikely(!skb)) {
SMSC_WARN(pdata, rx_err,
"Unable to allocate skb for rx packet");
@@ -1243,21 +1241,19 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
break;
}
- skb->data = skb->head;
- skb_reset_tail_pointer(skb);
-
- /* Align IP on 16B boundary */
- skb_reserve(skb, NET_IP_ALIGN);
- skb_put(skb, pktlength - 4);
+ skb_put(skb, pktwords << 2);
pdata->ops->rx_readfifo(pdata,
- (unsigned int *)skb->head, pktwords);
+ (unsigned int *)skb->data, pktwords);
+ skb_pull(skb, NET_IP_ALIGN);
+ skb_trim(skb, pktlength);
+
skb->protocol = eth_type_trans(skb, dev);
skb_checksum_none_assert(skb);
netif_receive_skb(skb);
/* Update counters */
dev->stats.rx_packets++;
- dev->stats.rx_bytes += (pktlength - 4);
+ dev->stats.rx_bytes += pktlength;
}
/* Return total received packets */
@@ -1565,7 +1561,7 @@ static int smsc911x_open(struct net_device *dev)
smsc911x_reg_write(pdata, FIFO_INT, temp);
/* set RX Data offset to 2 bytes for alignment */
- smsc911x_reg_write(pdata, RX_CFG, (2 << 8));
+ smsc911x_reg_write(pdata, RX_CFG, (NET_IP_ALIGN << 8));
/* enable NAPI polling before enabling RX interrupts */
napi_enable(&pdata->napi);
^ permalink raw reply related
* Re: [PATCH] net: smsc911x: fix RX FIFO fastforwarding when dropping packets
From: Eric Dumazet @ 2012-04-12 13:06 UTC (permalink / raw)
To: Will Deacon; +Cc: netdev@vger.kernel.org, Steve Glendinning
In-Reply-To: <20120412125355.GG16025@mudshark.cambridge.arm.com>
On Thu, 2012-04-12 at 13:53 +0100, Will Deacon wrote:
> Hi Eric,
>
> Thanks for taking a look.
>
> On Thu, Apr 12, 2012 at 10:20:48AM +0100, Eric Dumazet wrote:
> > On Thu, 2012-04-12 at 10:07 +0100, Will Deacon wrote:
> > > diff --git a/drivers/net/ethernet/smsc/smsc911x.c b/drivers/net/ethernet/smsc/smsc911x.c
> > > index 4a69710..b5599bc 100644
> > > --- a/drivers/net/ethernet/smsc/smsc911x.c
> > > +++ b/drivers/net/ethernet/smsc/smsc911x.c
> > > @@ -1228,7 +1228,7 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
> > > "Discarding packet with error bit set");
> > > /* Packet has an error, discard it and continue with
> > > * the next */
> > > - smsc911x_rx_fastforward(pdata, pktwords);
> > > + smsc911x_rx_fastforward(pdata, pktlength);
> > > dev->stats.rx_dropped++;
> > > continue;
> > > }
>
> [...]
>
> > Hum, looking at this driver, I see wrong code in lines 1246/1247
> >
> > skb->data = skb->head;
> > skb_reset_tail_pointer(skb);
> >
> > I suspect its hiding a buffer overflow bug or something.
>
> Yes, you're right.
>
> > netdev_alloc_skb() reserved NET_SKB_PAD bytes. A driver should not
> > un-reserve this headroom, or some networking setups can be very slow.
> >
> > So
> >
> > pdata->ops->rx_readfifo(pdata,
> > (unsigned int *)skb->head, pktwords);
> >
> > also should be fixed to use skb->data instead.
>
> Right, this seems to do the trick (and can replace my original patch by
> actually passing in the number of words to the fastforward function). I'm
> not sure whether the skb_trim is really required, but it makes the data
> format slightly clearer.
>
> It would be nice to get some input from Steve, but his email address seems
> to be bouncing at the moment.
>
> Will
>
>
> diff --git a/drivers/net/ethernet/smsc/smsc911x.c b/drivers/net/ethernet/smsc/smsc911x.c
> index 4a69710..3f43c24 100644
> --- a/drivers/net/ethernet/smsc/smsc911x.c
> +++ b/drivers/net/ethernet/smsc/smsc911x.c
> @@ -1166,10 +1166,8 @@ smsc911x_rx_counterrors(struct net_device *dev, unsigned int rxstat)
>
> /* Quickly dumps bad packets */
> static void
> -smsc911x_rx_fastforward(struct smsc911x_data *pdata, unsigned int pktbytes)
> +smsc911x_rx_fastforward(struct smsc911x_data *pdata, unsigned int pktwords)
> {
> - unsigned int pktwords = (pktbytes + NET_IP_ALIGN + 3) >> 2;
> -
> if (likely(pktwords >= 4)) {
> unsigned int timeout = 500;
> unsigned int val;
> @@ -1233,7 +1231,7 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
> continue;
> }
>
> - skb = netdev_alloc_skb(dev, pktlength + NET_IP_ALIGN);
> + skb = netdev_alloc_skb(dev, pktwords << 2);
> if (unlikely(!skb)) {
> SMSC_WARN(pdata, rx_err,
> "Unable to allocate skb for rx packet");
> @@ -1243,21 +1241,19 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
> break;
> }
>
> - skb->data = skb->head;
> - skb_reset_tail_pointer(skb);
> -
> - /* Align IP on 16B boundary */
> - skb_reserve(skb, NET_IP_ALIGN);
> - skb_put(skb, pktlength - 4);
> + skb_put(skb, pktwords << 2);
You could remove this line and do it after skb_reserve() ?
> pdata->ops->rx_readfifo(pdata,
> - (unsigned int *)skb->head, pktwords);
> + (unsigned int *)skb->data, pktwords);
> + skb_pull(skb, NET_IP_ALIGN);
skb_reserve(skb, NET_IP_ALIGN);
skb_put(skb, pktlength - 4);
> + skb_trim(skb, pktlength);
and remove this skb_trim()
> +
> skb->protocol = eth_type_trans(skb, dev);
> skb_checksum_none_assert(skb);
> netif_receive_skb(skb);
>
> /* Update counters */
> dev->stats.rx_packets++;
> - dev->stats.rx_bytes += (pktlength - 4);
> + dev->stats.rx_bytes += pktlength;
Some drivers account for the FCS, some dont, I guess you can leave the
line as is
> }
>
> /* Return total received packets */
> @@ -1565,7 +1561,7 @@ static int smsc911x_open(struct net_device *dev)
> smsc911x_reg_write(pdata, FIFO_INT, temp);
>
> /* set RX Data offset to 2 bytes for alignment */
> - smsc911x_reg_write(pdata, RX_CFG, (2 << 8));
> + smsc911x_reg_write(pdata, RX_CFG, (NET_IP_ALIGN << 8));
Good ;)
>
> /* enable NAPI polling before enabling RX interrupts */
> napi_enable(&pdata->napi);
>
Thanks
^ permalink raw reply
* Re: [RFC v3] Add TCP encap_rcv hook
From: Simon Horman @ 2012-04-12 13:10 UTC (permalink / raw)
To: Eric Dumazet; +Cc: dev-yBygre7rU0TnMu66kgdUjQ, netdev-u79uwXL29TY76Z2rM5mHXA
In-Reply-To: <1334218829.5300.5903.camel@edumazet-glaptop>
On Thu, Apr 12, 2012 at 10:20:29AM +0200, Eric Dumazet wrote:
> On Thu, 2012-04-12 at 16:42 +0900, Simon Horman wrote:
> > This hook is based on a hook of the same name provided by UDP. It provides
> > a way for to receive packets that have a TCP header and treat them in some
> > alternate way.
> >
> > It is intended to be used by an implementation of the STT tunneling
> > protocol within Open vSwtich's datapath. A prototype of such an
> > implementation has been made.
> >
> > The STT draft is available at
> > http://tools.ietf.org/html/draft-davie-stt-01
> >
> > My prototype STT implementation has been posted to the dev-UOEtcQmXneFl884UGnbwIQ@public.gmane.org
> > The first version can be found at:
> > http://www.mail-archive.com/dev-yBygre7rU0TnMu66kgdUjQ@public.gmane.org/msg08877.html
> >
> > Signed-off-by: Simon Horman <horms-/R6kz+dDXgpPR4JQBCEnsQ@public.gmane.org>
> >
>
> Hi Simon
>
> Oh well, this is insane :(
>
> > ---
> > include/linux/tcp.h | 3 +++
> > net/ipv4/tcp_ipv4.c | 23 ++++++++++++++++++++++-
> > 2 files changed, 25 insertions(+), 1 deletion(-)
> >
> > v3
> > * First post to netdev
> > * Replace more UDP references with TCP
> > * Move socket accesses to inside socket lock
> > and release lock on return.
> >
> > v2
> > * Fix comment to refer to TCP rather than UDP
> > * Allow skb to continue traversing the stack if
> > the encap_rcv callback returns a positive value.
> > This is the same behaviour as the UDP hook.
> >
> > diff --git a/include/linux/tcp.h b/include/linux/tcp.h
> > index b6c62d2..7210b23 100644
> > --- a/include/linux/tcp.h
> > +++ b/include/linux/tcp.h
> > @@ -472,6 +472,9 @@ struct tcp_sock {
> > * contains related tcp_cookie_transactions fields.
> > */
> > struct tcp_cookie_values *cookie_values;
> > +
> > + /* For encapsulation sockets. */
> > + int (*encap_rcv)(struct sock *sk, struct sk_buff *skb);
> > };
> >
>
> This adds a new cache miss for all incoming tcp frames...
>
> > static inline struct tcp_sock *tcp_sk(const struct sock *sk)
> > diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
> > index 3a25cf7..9898f71 100644
> > --- a/net/ipv4/tcp_ipv4.c
> > +++ b/net/ipv4/tcp_ipv4.c
> > @@ -1666,8 +1666,10 @@ int tcp_v4_rcv(struct sk_buff *skb)
> > const struct iphdr *iph;
> > const struct tcphdr *th;
> > struct sock *sk;
> > + struct tcp_sock *tp;
> > int ret;
> > struct net *net = dev_net(skb->dev);
> > + int (*encap_rcv)(struct sock *sk, struct sk_buff *skb);
> >
> > if (skb->pkt_type != PACKET_HOST)
> > goto discard_it;
> > @@ -1726,9 +1728,27 @@ process:
> >
> > bh_lock_sock_nested(sk);
> > ret = 0;
> > +
> > + tp = tcp_sk(sk);
> > + encap_rcv = ACCESS_ONCE(tp->encap_rcv);
> > + if (encap_rcv != NULL) {
>
> and a new conditional...
>
> > + /*
> > + * This is an encapsulation socket so pass the skb to
> > + * the socket's tcp_encap_rcv() hook. Otherwise, just
> > + * fall through and pass this up the TCP socket.
> > + * up->encap_rcv() returns the following value:
> > + * <=0 if skb was successfully passed to the encap
> > + * handler or was discarded by it.
> > + * >0 if skb should be passed on to TCP.
> > + */
> > + if (encap_rcv(sk, skb) <= 0) {
> > + ret = 0;
> > + goto unlock_sock;
> > + }
> > + }
> > +
> > if (!sock_owned_by_user(sk)) {
> > #ifdef CONFIG_NET_DMA
> > - struct tcp_sock *tp = tcp_sk(sk);
> > if (!tp->ucopy.dma_chan && tp->ucopy.pinned_list)
> > tp->ucopy.dma_chan = dma_find_channel(DMA_MEMCPY);
> > if (tp->ucopy.dma_chan)
> > @@ -1744,6 +1764,7 @@ process:
> > NET_INC_STATS_BH(net, LINUX_MIB_TCPBACKLOGDROP);
> > goto discard_and_relse;
> > }
> > +unlock_sock:
> > bh_unlock_sock(sk);
> >
> > sock_put(sk);
>
> I dont know, this sounds as a hack. Since you obviously spent a lot of
> time on this stuff, lets be constructive.
Hi Eric,
Thanks, I didn't really expect my patch to go in smoothly as is.
Though it may well be my first brush with insanity.
>
> I really suggest you take a look at <linux/static_key.h>
>
> So that on machines without any need for this encap_rcv, we dont even
> need to fetch tp->encap_rcv
>
> if (static_key_false(&stt_active)) {
> /* stt might be used on this socket */
> encap_rcv = ACCESS_ONCE(tp->encap_rcv);
> if (encap_rcv) {
> ...
> }
> }
>
> This way, if stt is not used/loaded, we have a single NOP
>
> If stt is used, NOP is patched to a JMP stt_code
>
>
> I probably implement this idea on UDP shortly so that you can have a
> reference for your implementation.
Thanks, I see your UDP code now. I'll see about getting the same thing
working for TCP.
^ permalink raw reply
* Re: Regression due to "ath9k: fix going to full-sleep on PS idle"
From: John W. Linville @ 2012-04-12 13:20 UTC (permalink / raw)
To: Sujith Manoharan
Cc: Linus Torvalds, Heinz Diehl, linux-kernel, Greg KH, akpm, alan,
linux-wireless Mailing List, ath9k-devel@lists.ath9k.org,
David Miller, Network Development
In-Reply-To: <20358.25376.230264.236893@gargle.gargle.HOWL>
On Thu, Apr 12, 2012 at 10:37:44AM +0530, Sujith Manoharan wrote:
> Linus Torvalds wrote:
> > You guys need to fix the subject line (like this), and make sure that
> > the right people are cc'd. This is not a "stable" issue - stable
> > cannot revert stuff that hasn't been reverted upstream.
> >
> > So instead of stable and Greg, it should be netdev and Davem.
> >
> > David/John: multiple people are complaining about that commit. It
> > really should be reverted, or a fix found. It's broken.
> >
> > I can do the revert, but it would be better coming from the networking people.
>
> John has already reverted the commit:
> http://git.kernel.org/?p=linux/kernel/git/linville/wireless.git;a=commit;h=011afa1ed8c408d694957d2474d89dc81a60b70c
Yes, I'll be pushing to Dave M shortly.
John
--
John W. Linville Someday the world will need a hero, and you
linville@tuxdriver.com might be all we have. Be ready.
^ permalink raw reply
* RFC udp: improve __udp4_lib_lookup performance
From: Alexandru Copot @ 2012-04-12 13:35 UTC (permalink / raw)
To: netdev
UDP uses 2 hashtables for fast socket lookup. First hash uses port as
a lookup key and the second one uses (port, addr).
When an UDP packet is received, the destination socket must be found to
deliver it. If there are many UDP sockets bound to INADDR_ANY, 2 hash
searches are made in the second hash: first one looks for the pair
(dest address, dest port) but doesn't find the socket; the second search
finds the socket by hashing (INADDR_ANY, dest port).
Those 2 searches can be avoided and a lot of time saved if instead we
searched directly in the first hash.
We could count the number of INADDR_ANY bound UDP sockets and
make only one search when that value is above a certain threshold. However,
if there are also sockets bound on a specific address, the second hash
won't be used and that might hurt performance for this case.
What is your opinion on this ? Would the performance gained by
counting INADDR_ANY bound sockets outweigh the loss in performance
for the case of mixed INADDR_ANY/specific address bound sockets ?
Alexandru Copot
^ permalink raw reply
* Re: [PATCH] 8139cp: set intr mask after its handler is registered
From: Flavio Leitner @ 2012-04-12 13:45 UTC (permalink / raw)
To: Jason Wang; +Cc: netdev, davem, linux-kernel
In-Reply-To: <20120412081053.25774.41676.stgit@amd-6168-8-1.englab.nay.redhat.com>
On Thu, 12 Apr 2012 16:10:54 +0800
Jason Wang <jasowang@redhat.com> wrote:
> We set intr mask before its handler is registered, this does not work well when
> 8139cp is sharing irq line with other devices. As the irq could be enabled by
> the device before 8139cp's hander is registered which may lead unhandled
> irq. Fix this by introducing an helper cp_irq_enable() and call it after
> request_irq().
>
> Signed-off-by: Jason Wang <jasowang@redhat.com>
Reviewed-by: Flavio Leitner <fbl@redhat.com>
fbl
^ permalink raw reply
* [PATCH] Phonet: change maintainer address
From: Rémi Denis-Courmont @ 2012-04-12 13:39 UTC (permalink / raw)
To: netdev; +Cc: Rémi Denis-Courmont
In-Reply-To: <1334237958-22855-1-git-send-email-remi@remlab.net>
From: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
nokia.com MX does not cope well with kernel.org.
Signed-off-by: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
---
MAINTAINERS | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/MAINTAINERS b/MAINTAINERS
index d710c00..74f753e 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -5197,7 +5197,7 @@ S: Maintained
F: include/linux/personality.h
PHONET PROTOCOL
-M: Remi Denis-Courmont <remi.denis-courmont@nokia.com>
+M: Remi Denis-Courmont <courmisch@gmail.com>
S: Supported
F: Documentation/networking/phonet.txt
F: include/linux/phonet.h
--
1.7.5.4
^ permalink raw reply related
* [PATCH] Phonet: missing headers (sparse)
From: Rémi Denis-Courmont @ 2012-04-12 13:39 UTC (permalink / raw)
To: netdev; +Cc: Rémi Denis-Courmont
In-Reply-To: <1334237958-22855-1-git-send-email-remi@remlab.net>
From: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
Signed-off-by: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
---
net/phonet/sysctl.c | 4 ++++
1 files changed, 4 insertions(+), 0 deletions(-)
diff --git a/net/phonet/sysctl.c b/net/phonet/sysctl.c
index cea1c7d..740bf20 100644
--- a/net/phonet/sysctl.c
+++ b/net/phonet/sysctl.c
@@ -27,6 +27,10 @@
#include <linux/errno.h>
#include <linux/init.h>
+#include <net/sock.h>
+#include <linux/phonet.h>
+#include <net/phonet/phonet.h>
+
#define DYNAMIC_PORT_MIN 0x40
#define DYNAMIC_PORT_MAX 0x7f
--
1.7.5.4
^ permalink raw reply related
* [PATCH] Phonet: phonet_net_id can be static (sparse)
From: Rémi Denis-Courmont @ 2012-04-12 13:39 UTC (permalink / raw)
To: netdev; +Cc: Rémi Denis-Courmont
From: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
Signed-off-by: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
---
net/phonet/pn_dev.c | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/net/phonet/pn_dev.c b/net/phonet/pn_dev.c
index 9b9a85e..631cd51 100644
--- a/net/phonet/pn_dev.c
+++ b/net/phonet/pn_dev.c
@@ -44,7 +44,7 @@ struct phonet_net {
struct phonet_routes routes;
};
-int phonet_net_id __read_mostly;
+static int phonet_net_id __read_mostly;
static struct phonet_net *phonet_pernet(struct net *net)
{
--
1.7.5.4
^ permalink raw reply related
* Re: [PATCH] net: smsc911x: fix RX FIFO fastforwarding when dropping packets
From: Will Deacon @ 2012-04-12 13:47 UTC (permalink / raw)
To: Eric Dumazet; +Cc: netdev@vger.kernel.org, Steve Glendinning
In-Reply-To: <1334235963.5300.6361.camel@edumazet-glaptop>
On Thu, Apr 12, 2012 at 02:06:03PM +0100, Eric Dumazet wrote:
> On Thu, 2012-04-12 at 13:53 +0100, Will Deacon wrote:
> > diff --git a/drivers/net/ethernet/smsc/smsc911x.c b/drivers/net/ethernet/smsc/smsc911x.c
> > index 4a69710..3f43c24 100644
> > --- a/drivers/net/ethernet/smsc/smsc911x.c
> > +++ b/drivers/net/ethernet/smsc/smsc911x.c
> > @@ -1166,10 +1166,8 @@ smsc911x_rx_counterrors(struct net_device *dev, unsigned int rxstat)
[...]
> > - skb->data = skb->head;
> > - skb_reset_tail_pointer(skb);
> > -
> > - /* Align IP on 16B boundary */
> > - skb_reserve(skb, NET_IP_ALIGN);
> > - skb_put(skb, pktlength - 4);
> > + skb_put(skb, pktwords << 2);
>
> You could remove this line and do it after skb_reserve() ?
>
> > pdata->ops->rx_readfifo(pdata,
> > - (unsigned int *)skb->head, pktwords);
> > + (unsigned int *)skb->data, pktwords);
> > + skb_pull(skb, NET_IP_ALIGN);
>
> skb_reserve(skb, NET_IP_ALIGN);
I don't think we want an skb_reserve at all, since the hardware shifts the
data in the RX FIFO, meaning that we will read two bytes of 0 anyway before
valid data.
> skb_put(skb, pktlength - 4);
I can move the put here if you like, but we need to use pktwords << 2 to
make sure that we read the leading and trailing zeroes inserted by the
hardware.
> > + skb_trim(skb, pktlength);
>
> and remove this skb_trim()
Can do, just thought it might help illustrate that we might have some padding
at the end.
> > /* Update counters */
> > dev->stats.rx_packets++;
> > - dev->stats.rx_bytes += (pktlength - 4);
> > + dev->stats.rx_bytes += pktlength;
>
> Some drivers account for the FCS, some dont, I guess you can leave the
> line as is
Sure.
Thanks for the comments,
Will
^ permalink raw reply
* Powerd Cloud Hosting and Server
From: woody @ 2012-04-12 13:34 UTC (permalink / raw)
Dear All,
We are one of the top Cloud Solution provider base in Hong Kong, with over 10+ years experience,
we providing better than good and lower cost service of CLoud Hosting (Cloud Server / Hosting / CDN)
Starting at $1.99, let's come to experience and enjoy our powerful cloud system.
Thanks for your time and appreciated to look arround our website.
http://www.cloudluca.com/
Best Regards,
The 36cloud Team
If you do not wish to further receive this event message, email "subscriber@dedicatedserver.com.hk" to unsubscribe this message or revoe your email from the list.
^ permalink raw reply
* Re: RFC udp: improve __udp4_lib_lookup performance
From: Eric Dumazet @ 2012-04-12 14:00 UTC (permalink / raw)
To: Alexandru Copot; +Cc: netdev
In-Reply-To: <CAHG7+CAt_YjxUp6+u9J47Ti1HA6hh_UkRMWQsXw4AsbEkvCu7w@mail.gmail.com>
On Thu, 2012-04-12 at 16:35 +0300, Alexandru Copot wrote:
> UDP uses 2 hashtables for fast socket lookup. First hash uses port as
> a lookup key and the second one uses (port, addr).
>
> When an UDP packet is received, the destination socket must be found to
> deliver it. If there are many UDP sockets bound to INADDR_ANY, 2 hash
> searches are made in the second hash: first one looks for the pair
> (dest address, dest port) but doesn't find the socket; the second search
> finds the socket by hashing (INADDR_ANY, dest port).
>
> Those 2 searches can be avoided and a lot of time saved if instead we
> searched directly in the first hash.
>
> We could count the number of INADDR_ANY bound UDP sockets and
> make only one search when that value is above a certain threshold. However,
> if there are also sockets bound on a specific address, the second hash
> won't be used and that might hurt performance for this case.
>
> What is your opinion on this ? Would the performance gained by
> counting INADDR_ANY bound sockets outweigh the loss in performance
> for the case of mixed INADDR_ANY/specific address bound sockets ?
I have no idea of your workload, but existing code is already very
optimized.
udp4_lib_lookup2() variants are only called when (hslot->count > 10)
If your workload have one 60000 UDP sockets bound on INADDR_ANY, I
suggest you check udp hash size and eventually increase it to the max ?
dmesg | grep "UDP hash"
Boot command : uhash_entries=65536
^ permalink raw reply
* Re: [PATCH] net: smsc911x: fix RX FIFO fastforwarding when dropping packets
From: Eric Dumazet @ 2012-04-12 14:01 UTC (permalink / raw)
To: Will Deacon; +Cc: netdev@vger.kernel.org, Steve Glendinning
In-Reply-To: <20120412134757.GH16025@mudshark.cambridge.arm.com>
On Thu, 2012-04-12 at 14:47 +0100, Will Deacon wrote:
>
> I don't think we want an skb_reserve at all, since the hardware shifts the
> data in the RX FIFO, meaning that we will read two bytes of 0 anyway before
> valid data.
>
> > skb_put(skb, pktlength - 4);
>
> I can move the put here if you like, but we need to use pktwords << 2 to
> make sure that we read the leading and trailing zeroes inserted by the
> hardware.
before calling linux stack, you'll have to skip those 2 bytes.
This is skb_reserve() purpose.
^ permalink raw reply
* pull request: wireless 2012-04-12
From: John W. Linville @ 2012-04-12 14:28 UTC (permalink / raw)
To: davem; +Cc: linux-wireless, netdev, linux-kernel
[-- Attachment #1: Type: text/plain, Size: 30364 bytes --]
commit 5d949944229b0a08e218723be231731cd86b94f3
Dave,
This is a flurry of fixes intended for 3.4...
Many of these are Bluetooth fixes. Gustavo says:
"This is a batch of fixes for 3.4. We have added support to 3 new
devices, fixes some NULL-pointer dereferences, memory leaks, memory
corruption and endian bugs. There was also a userspace compatibility
fix reported by Keith Packard on lkml. The fixes are all simple."
On top of the Bluetooths bits, we have a number of wireless fixes.
One is an rt2x00 fix from Chien-Chia Chen which fixes the rfkill
registration so that it still works even if the box is booted with the
device already blocked. Johannes Berg gives us a pair of fixes, one
that corrects a macro parameter when setting a beacon wait timeout, and
another that ensures that the proper interface state is used throughout
nl80211 so as to avoid warnings and unintended driver behavior.
Julia Lawall gives us a fix for a memory leak in an error handling
case. Larry Finger is the star performer for this round, giving us a
fix for firmware initialization in rtl8192de, a mac80211 fix to quiet
some log spam, a fix to avoid a NULL pointer dereference in rtlwifi, an
rtlwifi fix to avoid a "sleeping function called from invalid context"
BUG, and another rtlwifi fix to avoid "Out of SW-IOMMU space" errors.
Paul Gortmaker gives us a fix to avoid bcma build breakage on MIPS.
Samuel Ortiz fixes a loop in NFC's LLCP Tx frame fragmentation loop.
And finally, Sujith Manoharan reverts an earlier patch in order to
fix a regression reported by a number of ath9k users.
Please let me know if there are problems!
Thanks,
John
---
The following changes since commit a21d45726acacc963d8baddf74607d9b74e2b723:
tcp: avoid order-1 allocations on wifi and tx path (2012-04-11 10:11:12 -0400)
are available in the git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/linville/wireless.git for-davem
AceLan Kao (1):
Bluetooth: Add support for Atheros [04ca:3005]
Andrei Emeltchenko (3):
Bluetooth: Fix memory leaks due to chan refcnt
Bluetooth: mgmt: Add missing endian conversion
Bluetooth: mgmt: Fix timeout type
Brian Gix (1):
Bluetooth: mgmt: Fix corruption of device_connected pkt
Chen, Chien-Chia (1):
rt2x00: Fix rfkill_polling register function.
Cho, Yu-Chen (1):
Bluetooth: Add Atheros maryann PIDVID support
Don Zickus (1):
Bluetooth: btusb: typo in Broadcom SoftSailing id
Gustavo Padovan (1):
Bluetooth: Fix userspace compatibility issue with mgmt interface
Hemant Gupta (1):
Bluetooth: Use correct flags for checking HCI_SSP_ENABLED bit
Johan Hedberg (2):
Bluetooth: Don't increment twice in eir_has_data_type()
Bluetooth: Check for minimum data length in eir_has_data_type()
Johan Hovold (2):
Bluetooth: hci_ldisc: fix NULL-pointer dereference on tty_close
Bluetooth: hci_core: fix NULL-pointer dereference at unregister
Johannes Berg (2):
mac80211: fix association beacon wait timeout
nl80211: ensure interface is up in various APIs
John W. Linville (2):
Merge branch 'master' of git://git.kernel.org/.../bluetooth/bluetooth
Merge branch 'master' of git://git.kernel.org/.../linville/wireless into for-davem
João Paulo Rechi Vita (1):
Bluetooth: btusb: Add USB device ID "0a5c 21e8"
Julia Lawall (1):
net/wireless/wext-core.c: add missing kfree
Larry Finger (5):
rtlwifi: rtl8192de: Fix firmware initialization
mac80211: Convert WARN_ON to WARN_ON_ONCE
rtlwifi: Fix oops on rate-control failure
rtlwifi: Preallocate USB read buffers and eliminate kalloc in read routine
rtlwifi: Add missing DMA buffer unmapping for PCI drivers
Marcel Holtmann (1):
MAINTAINERS: update Bluetooth tree locations
Paul Gortmaker (1):
bcma: fix build error on MIPS; implicit pcibios_enable_device
Samuel Ortiz (1):
NFC: Fix the LLCP Tx fragmentation loop
Santosh Nayak (1):
Bluetooth: Fix Endian Bug.
Sujith Manoharan (1):
Revert "ath9k: fix going to full-sleep on PS idle"
MAINTAINERS | 8 +++---
drivers/bcma/Kconfig | 2 +-
drivers/bcma/driver_pci_host.c | 1 +
drivers/bluetooth/ath3k.c | 4 +++
drivers/bluetooth/btusb.c | 5 +++-
drivers/bluetooth/hci_ldisc.c | 2 +-
drivers/net/wireless/ath/ath9k/main.c | 8 ++----
drivers/net/wireless/rt2x00/rt2x00dev.c | 6 +----
drivers/net/wireless/rtlwifi/base.c | 5 +++-
drivers/net/wireless/rtlwifi/pci.c | 7 ++++-
drivers/net/wireless/rtlwifi/rtl8192de/sw.c | 6 ----
drivers/net/wireless/rtlwifi/usb.c | 34 ++++++++++++--------------
drivers/net/wireless/rtlwifi/wifi.h | 6 ++++-
include/net/bluetooth/hci.h | 3 +-
include/net/bluetooth/hci_core.h | 12 +++++----
include/net/bluetooth/mgmt.h | 2 +-
include/net/mac80211.h | 2 +-
net/bluetooth/hci_core.c | 7 +++++
net/bluetooth/l2cap_core.c | 3 ++
net/bluetooth/l2cap_sock.c | 5 ++-
net/bluetooth/mgmt.c | 13 +++++++---
net/mac80211/mlme.c | 3 +-
net/nfc/llcp/commands.c | 4 +-
net/wireless/nl80211.c | 31 ++++++++++++++----------
net/wireless/wext-core.c | 6 +++-
25 files changed, 108 insertions(+), 77 deletions(-)
diff --git a/MAINTAINERS b/MAINTAINERS
index 71b7f5c..0e2f300 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -1521,8 +1521,8 @@ M: Gustavo Padovan <gustavo@padovan.org>
M: Johan Hedberg <johan.hedberg@gmail.com>
L: linux-bluetooth@vger.kernel.org
W: http://www.bluez.org/
-T: git git://git.kernel.org/pub/scm/linux/kernel/git/padovan/bluetooth.git
-T: git git://git.kernel.org/pub/scm/linux/kernel/git/jh/bluetooth.git
+T: git git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth.git
+T: git git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git
S: Maintained
F: drivers/bluetooth/
@@ -1532,8 +1532,8 @@ M: Gustavo Padovan <gustavo@padovan.org>
M: Johan Hedberg <johan.hedberg@gmail.com>
L: linux-bluetooth@vger.kernel.org
W: http://www.bluez.org/
-T: git git://git.kernel.org/pub/scm/linux/kernel/git/padovan/bluetooth.git
-T: git git://git.kernel.org/pub/scm/linux/kernel/git/jh/bluetooth.git
+T: git git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth.git
+T: git git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git
S: Maintained
F: net/bluetooth/
F: include/net/bluetooth/
diff --git a/drivers/bcma/Kconfig b/drivers/bcma/Kconfig
index c1172da..fb7c80f 100644
--- a/drivers/bcma/Kconfig
+++ b/drivers/bcma/Kconfig
@@ -29,7 +29,7 @@ config BCMA_HOST_PCI
config BCMA_DRIVER_PCI_HOSTMODE
bool "Driver for PCI core working in hostmode"
- depends on BCMA && MIPS
+ depends on BCMA && MIPS && BCMA_HOST_PCI
help
PCI core hostmode operation (external PCI bus).
diff --git a/drivers/bcma/driver_pci_host.c b/drivers/bcma/driver_pci_host.c
index 4e20bcf..d2097a1 100644
--- a/drivers/bcma/driver_pci_host.c
+++ b/drivers/bcma/driver_pci_host.c
@@ -10,6 +10,7 @@
*/
#include "bcma_private.h"
+#include <linux/pci.h>
#include <linux/export.h>
#include <linux/bcma/bcma.h>
#include <asm/paccess.h>
diff --git a/drivers/bluetooth/ath3k.c b/drivers/bluetooth/ath3k.c
index 4844247..ae9edca 100644
--- a/drivers/bluetooth/ath3k.c
+++ b/drivers/bluetooth/ath3k.c
@@ -72,7 +72,9 @@ static struct usb_device_id ath3k_table[] = {
/* Atheros AR3012 with sflash firmware*/
{ USB_DEVICE(0x0CF3, 0x3004) },
+ { USB_DEVICE(0x0CF3, 0x311D) },
{ USB_DEVICE(0x13d3, 0x3375) },
+ { USB_DEVICE(0x04CA, 0x3005) },
/* Atheros AR5BBU12 with sflash firmware */
{ USB_DEVICE(0x0489, 0xE02C) },
@@ -89,7 +91,9 @@ static struct usb_device_id ath3k_blist_tbl[] = {
/* Atheros AR3012 with sflash firmware*/
{ USB_DEVICE(0x0cf3, 0x3004), .driver_info = BTUSB_ATH3012 },
+ { USB_DEVICE(0x0cf3, 0x311D), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3375), .driver_info = BTUSB_ATH3012 },
+ { USB_DEVICE(0x04ca, 0x3005), .driver_info = BTUSB_ATH3012 },
{ } /* Terminating entry */
};
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 480cad9..3311b81 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -61,7 +61,7 @@ static struct usb_device_id btusb_table[] = {
{ USB_DEVICE_INFO(0xe0, 0x01, 0x01) },
/* Broadcom SoftSailing reporting vendor specific */
- { USB_DEVICE(0x05ac, 0x21e1) },
+ { USB_DEVICE(0x0a5c, 0x21e1) },
/* Apple MacBookPro 7,1 */
{ USB_DEVICE(0x05ac, 0x8213) },
@@ -103,6 +103,7 @@ static struct usb_device_id btusb_table[] = {
/* Broadcom BCM20702A0 */
{ USB_DEVICE(0x0a5c, 0x21e3) },
{ USB_DEVICE(0x0a5c, 0x21e6) },
+ { USB_DEVICE(0x0a5c, 0x21e8) },
{ USB_DEVICE(0x0a5c, 0x21f3) },
{ USB_DEVICE(0x413c, 0x8197) },
@@ -129,7 +130,9 @@ static struct usb_device_id blacklist_table[] = {
/* Atheros 3012 with sflash firmware */
{ USB_DEVICE(0x0cf3, 0x3004), .driver_info = BTUSB_ATH3012 },
+ { USB_DEVICE(0x0cf3, 0x311d), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3375), .driver_info = BTUSB_ATH3012 },
+ { USB_DEVICE(0x04ca, 0x3005), .driver_info = BTUSB_ATH3012 },
/* Atheros AR5BBU12 with sflash firmware */
{ USB_DEVICE(0x0489, 0xe02c), .driver_info = BTUSB_IGNORE },
diff --git a/drivers/bluetooth/hci_ldisc.c b/drivers/bluetooth/hci_ldisc.c
index fd5adb4..98a8c05 100644
--- a/drivers/bluetooth/hci_ldisc.c
+++ b/drivers/bluetooth/hci_ldisc.c
@@ -299,11 +299,11 @@ static void hci_uart_tty_close(struct tty_struct *tty)
hci_uart_close(hdev);
if (test_and_clear_bit(HCI_UART_PROTO_SET, &hu->flags)) {
- hu->proto->close(hu);
if (hdev) {
hci_unregister_dev(hdev);
hci_free_dev(hdev);
}
+ hu->proto->close(hu);
}
kfree(hu);
diff --git a/drivers/net/wireless/ath/ath9k/main.c b/drivers/net/wireless/ath/ath9k/main.c
index 215eb25..2504ab0 100644
--- a/drivers/net/wireless/ath/ath9k/main.c
+++ b/drivers/net/wireless/ath/ath9k/main.c
@@ -118,15 +118,13 @@ void ath9k_ps_restore(struct ath_softc *sc)
if (--sc->ps_usecount != 0)
goto unlock;
- if (sc->ps_flags & PS_WAIT_FOR_TX_ACK)
- goto unlock;
-
- if (sc->ps_idle)
+ if (sc->ps_idle && (sc->ps_flags & PS_WAIT_FOR_TX_ACK))
mode = ATH9K_PM_FULL_SLEEP;
else if (sc->ps_enabled &&
!(sc->ps_flags & (PS_WAIT_FOR_BEACON |
PS_WAIT_FOR_CAB |
- PS_WAIT_FOR_PSPOLL_DATA)))
+ PS_WAIT_FOR_PSPOLL_DATA |
+ PS_WAIT_FOR_TX_ACK)))
mode = ATH9K_PM_NETWORK_SLEEP;
else
goto unlock;
diff --git a/drivers/net/wireless/rt2x00/rt2x00dev.c b/drivers/net/wireless/rt2x00/rt2x00dev.c
index fc9901e..90cc5e7 100644
--- a/drivers/net/wireless/rt2x00/rt2x00dev.c
+++ b/drivers/net/wireless/rt2x00/rt2x00dev.c
@@ -1062,11 +1062,6 @@ static int rt2x00lib_initialize(struct rt2x00_dev *rt2x00dev)
set_bit(DEVICE_STATE_INITIALIZED, &rt2x00dev->flags);
- /*
- * Register the extra components.
- */
- rt2x00rfkill_register(rt2x00dev);
-
return 0;
}
@@ -1210,6 +1205,7 @@ int rt2x00lib_probe_dev(struct rt2x00_dev *rt2x00dev)
rt2x00link_register(rt2x00dev);
rt2x00leds_register(rt2x00dev);
rt2x00debug_register(rt2x00dev);
+ rt2x00rfkill_register(rt2x00dev);
return 0;
diff --git a/drivers/net/wireless/rtlwifi/base.c b/drivers/net/wireless/rtlwifi/base.c
index 5100235..e54488d 100644
--- a/drivers/net/wireless/rtlwifi/base.c
+++ b/drivers/net/wireless/rtlwifi/base.c
@@ -838,7 +838,10 @@ void rtl_get_tcb_desc(struct ieee80211_hw *hw,
__le16 fc = hdr->frame_control;
txrate = ieee80211_get_tx_rate(hw, info);
- tcb_desc->hw_rate = txrate->hw_value;
+ if (txrate)
+ tcb_desc->hw_rate = txrate->hw_value;
+ else
+ tcb_desc->hw_rate = 0;
if (ieee80211_is_data(fc)) {
/*
diff --git a/drivers/net/wireless/rtlwifi/pci.c b/drivers/net/wireless/rtlwifi/pci.c
index 07dd38e..288b035 100644
--- a/drivers/net/wireless/rtlwifi/pci.c
+++ b/drivers/net/wireless/rtlwifi/pci.c
@@ -912,8 +912,13 @@ static void _rtl_pci_prepare_bcn_tasklet(struct ieee80211_hw *hw)
memset(&tcb_desc, 0, sizeof(struct rtl_tcb_desc));
ring = &rtlpci->tx_ring[BEACON_QUEUE];
pskb = __skb_dequeue(&ring->queue);
- if (pskb)
+ if (pskb) {
+ struct rtl_tx_desc *entry = &ring->desc[ring->idx];
+ pci_unmap_single(rtlpci->pdev, rtlpriv->cfg->ops->get_desc(
+ (u8 *) entry, true, HW_DESC_TXBUFF_ADDR),
+ pskb->len, PCI_DMA_TODEVICE);
kfree_skb(pskb);
+ }
/*NB: the beacon data buffer must be 32-bit aligned. */
pskb = ieee80211_beacon_get(hw, mac->vif);
diff --git a/drivers/net/wireless/rtlwifi/rtl8192de/sw.c b/drivers/net/wireless/rtlwifi/rtl8192de/sw.c
index 4898c50..480862c 100644
--- a/drivers/net/wireless/rtlwifi/rtl8192de/sw.c
+++ b/drivers/net/wireless/rtlwifi/rtl8192de/sw.c
@@ -91,7 +91,6 @@ static int rtl92d_init_sw_vars(struct ieee80211_hw *hw)
u8 tid;
struct rtl_priv *rtlpriv = rtl_priv(hw);
struct rtl_pci *rtlpci = rtl_pcidev(rtl_pcipriv(hw));
- static int header_print;
rtlpriv->dm.dm_initialgain_enable = true;
rtlpriv->dm.dm_flag = 0;
@@ -171,10 +170,6 @@ static int rtl92d_init_sw_vars(struct ieee80211_hw *hw)
for (tid = 0; tid < 8; tid++)
skb_queue_head_init(&rtlpriv->mac80211.skb_waitq[tid]);
- /* Only load firmware for first MAC */
- if (header_print)
- return 0;
-
/* for firmware buf */
rtlpriv->rtlhal.pfirmware = vzalloc(0x8000);
if (!rtlpriv->rtlhal.pfirmware) {
@@ -186,7 +181,6 @@ static int rtl92d_init_sw_vars(struct ieee80211_hw *hw)
rtlpriv->max_fw_size = 0x8000;
pr_info("Driver for Realtek RTL8192DE WLAN interface\n");
pr_info("Loading firmware file %s\n", rtlpriv->cfg->fw_name);
- header_print++;
/* request fw */
err = request_firmware_nowait(THIS_MODULE, 1, rtlpriv->cfg->fw_name,
diff --git a/drivers/net/wireless/rtlwifi/usb.c b/drivers/net/wireless/rtlwifi/usb.c
index 2e1e352..d04dbda 100644
--- a/drivers/net/wireless/rtlwifi/usb.c
+++ b/drivers/net/wireless/rtlwifi/usb.c
@@ -124,46 +124,38 @@ static int _usbctrl_vendorreq_sync_read(struct usb_device *udev, u8 request,
return status;
}
-static u32 _usb_read_sync(struct usb_device *udev, u32 addr, u16 len)
+static u32 _usb_read_sync(struct rtl_priv *rtlpriv, u32 addr, u16 len)
{
+ struct device *dev = rtlpriv->io.dev;
+ struct usb_device *udev = to_usb_device(dev);
u8 request;
u16 wvalue;
u16 index;
- u32 *data;
- u32 ret;
+ __le32 *data = &rtlpriv->usb_data[rtlpriv->usb_data_index];
- data = kmalloc(sizeof(u32), GFP_KERNEL);
- if (!data)
- return -ENOMEM;
request = REALTEK_USB_VENQT_CMD_REQ;
index = REALTEK_USB_VENQT_CMD_IDX; /* n/a */
wvalue = (u16)addr;
_usbctrl_vendorreq_sync_read(udev, request, wvalue, index, data, len);
- ret = le32_to_cpu(*data);
- kfree(data);
- return ret;
+ if (++rtlpriv->usb_data_index >= RTL_USB_MAX_RX_COUNT)
+ rtlpriv->usb_data_index = 0;
+ return le32_to_cpu(*data);
}
static u8 _usb_read8_sync(struct rtl_priv *rtlpriv, u32 addr)
{
- struct device *dev = rtlpriv->io.dev;
-
- return (u8)_usb_read_sync(to_usb_device(dev), addr, 1);
+ return (u8)_usb_read_sync(rtlpriv, addr, 1);
}
static u16 _usb_read16_sync(struct rtl_priv *rtlpriv, u32 addr)
{
- struct device *dev = rtlpriv->io.dev;
-
- return (u16)_usb_read_sync(to_usb_device(dev), addr, 2);
+ return (u16)_usb_read_sync(rtlpriv, addr, 2);
}
static u32 _usb_read32_sync(struct rtl_priv *rtlpriv, u32 addr)
{
- struct device *dev = rtlpriv->io.dev;
-
- return _usb_read_sync(to_usb_device(dev), addr, 4);
+ return _usb_read_sync(rtlpriv, addr, 4);
}
static void _usb_write_async(struct usb_device *udev, u32 addr, u32 val,
@@ -955,6 +947,11 @@ int __devinit rtl_usb_probe(struct usb_interface *intf,
return -ENOMEM;
}
rtlpriv = hw->priv;
+ rtlpriv->usb_data = kzalloc(RTL_USB_MAX_RX_COUNT * sizeof(u32),
+ GFP_KERNEL);
+ if (!rtlpriv->usb_data)
+ return -ENOMEM;
+ rtlpriv->usb_data_index = 0;
init_completion(&rtlpriv->firmware_loading_complete);
SET_IEEE80211_DEV(hw, &intf->dev);
udev = interface_to_usbdev(intf);
@@ -1025,6 +1022,7 @@ void rtl_usb_disconnect(struct usb_interface *intf)
/* rtl_deinit_rfkill(hw); */
rtl_usb_deinit(hw);
rtl_deinit_core(hw);
+ kfree(rtlpriv->usb_data);
rtlpriv->cfg->ops->deinit_sw_leds(hw);
rtlpriv->cfg->ops->deinit_sw_vars(hw);
_rtl_usb_io_handler_release(hw);
diff --git a/drivers/net/wireless/rtlwifi/wifi.h b/drivers/net/wireless/rtlwifi/wifi.h
index b591614..28ebc69 100644
--- a/drivers/net/wireless/rtlwifi/wifi.h
+++ b/drivers/net/wireless/rtlwifi/wifi.h
@@ -67,7 +67,7 @@
#define QOS_QUEUE_NUM 4
#define RTL_MAC80211_NUM_QUEUE 5
#define REALTEK_USB_VENQT_MAX_BUF_SIZE 254
-
+#define RTL_USB_MAX_RX_COUNT 100
#define QBSS_LOAD_SIZE 5
#define MAX_WMMELE_LENGTH 64
@@ -1629,6 +1629,10 @@ struct rtl_priv {
interface or hardware */
unsigned long status;
+ /* data buffer pointer for USB reads */
+ __le32 *usb_data;
+ int usb_data_index;
+
/*This must be the last item so
that it points to the data allocated
beyond this structure like:
diff --git a/include/net/bluetooth/hci.h b/include/net/bluetooth/hci.h
index 344b0f9..d47e523 100644
--- a/include/net/bluetooth/hci.h
+++ b/include/net/bluetooth/hci.h
@@ -92,6 +92,7 @@ enum {
HCI_SERVICE_CACHE,
HCI_LINK_KEYS,
HCI_DEBUG_KEYS,
+ HCI_UNREGISTER,
HCI_LE_SCAN,
HCI_SSP_ENABLED,
@@ -1327,8 +1328,8 @@ struct sockaddr_hci {
#define HCI_DEV_NONE 0xffff
#define HCI_CHANNEL_RAW 0
-#define HCI_CHANNEL_CONTROL 1
#define HCI_CHANNEL_MONITOR 2
+#define HCI_CHANNEL_CONTROL 3
struct hci_filter {
unsigned long type_mask;
diff --git a/include/net/bluetooth/hci_core.h b/include/net/bluetooth/hci_core.h
index daefaac..6822d25 100644
--- a/include/net/bluetooth/hci_core.h
+++ b/include/net/bluetooth/hci_core.h
@@ -427,7 +427,7 @@ enum {
static inline bool hci_conn_ssp_enabled(struct hci_conn *conn)
{
struct hci_dev *hdev = conn->hdev;
- return (test_bit(HCI_SSP_ENABLED, &hdev->flags) &&
+ return (test_bit(HCI_SSP_ENABLED, &hdev->dev_flags) &&
test_bit(HCI_CONN_SSP_ENABLED, &conn->flags));
}
@@ -907,11 +907,13 @@ static inline void hci_role_switch_cfm(struct hci_conn *conn, __u8 status,
static inline bool eir_has_data_type(u8 *data, size_t data_len, u8 type)
{
- u8 field_len;
- size_t parsed;
+ size_t parsed = 0;
- for (parsed = 0; parsed < data_len - 1; parsed += field_len) {
- field_len = data[0];
+ if (data_len < 2)
+ return false;
+
+ while (parsed < data_len - 1) {
+ u8 field_len = data[0];
if (field_len == 0)
break;
diff --git a/include/net/bluetooth/mgmt.h b/include/net/bluetooth/mgmt.h
index ffc1377..ebfd91f 100644
--- a/include/net/bluetooth/mgmt.h
+++ b/include/net/bluetooth/mgmt.h
@@ -117,7 +117,7 @@ struct mgmt_mode {
#define MGMT_OP_SET_DISCOVERABLE 0x0006
struct mgmt_cp_set_discoverable {
__u8 val;
- __u16 timeout;
+ __le16 timeout;
} __packed;
#define MGMT_SET_DISCOVERABLE_SIZE 3
diff --git a/include/net/mac80211.h b/include/net/mac80211.h
index 87d203f..9210bdc 100644
--- a/include/net/mac80211.h
+++ b/include/net/mac80211.h
@@ -1327,7 +1327,7 @@ static inline struct ieee80211_rate *
ieee80211_get_tx_rate(const struct ieee80211_hw *hw,
const struct ieee80211_tx_info *c)
{
- if (WARN_ON(c->control.rates[0].idx < 0))
+ if (WARN_ON_ONCE(c->control.rates[0].idx < 0))
return NULL;
return &hw->wiphy->bands[c->band]->bitrates[c->control.rates[0].idx];
}
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index e33af63..92a857e 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -665,6 +665,11 @@ int hci_dev_open(__u16 dev)
hci_req_lock(hdev);
+ if (test_bit(HCI_UNREGISTER, &hdev->dev_flags)) {
+ ret = -ENODEV;
+ goto done;
+ }
+
if (hdev->rfkill && rfkill_blocked(hdev->rfkill)) {
ret = -ERFKILL;
goto done;
@@ -1849,6 +1854,8 @@ void hci_unregister_dev(struct hci_dev *hdev)
BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
+ set_bit(HCI_UNREGISTER, &hdev->dev_flags);
+
write_lock(&hci_dev_list_lock);
list_del(&hdev->list);
write_unlock(&hci_dev_list_lock);
diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c
index b8e17e4..94552b3 100644
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -1308,6 +1308,7 @@ static void l2cap_monitor_timeout(struct work_struct *work)
if (chan->retry_count >= chan->remote_max_tx) {
l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
l2cap_chan_unlock(chan);
+ l2cap_chan_put(chan);
return;
}
@@ -1316,6 +1317,7 @@ static void l2cap_monitor_timeout(struct work_struct *work)
l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
l2cap_chan_unlock(chan);
+ l2cap_chan_put(chan);
}
static void l2cap_retrans_timeout(struct work_struct *work)
@@ -1335,6 +1337,7 @@ static void l2cap_retrans_timeout(struct work_struct *work)
l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
l2cap_chan_unlock(chan);
+ l2cap_chan_put(chan);
}
static void l2cap_drop_acked_frames(struct l2cap_chan *chan)
diff --git a/net/bluetooth/l2cap_sock.c b/net/bluetooth/l2cap_sock.c
index c4fe583..29122ed 100644
--- a/net/bluetooth/l2cap_sock.c
+++ b/net/bluetooth/l2cap_sock.c
@@ -82,7 +82,7 @@ static int l2cap_sock_bind(struct socket *sock, struct sockaddr *addr, int alen)
}
if (la.l2_cid)
- err = l2cap_add_scid(chan, la.l2_cid);
+ err = l2cap_add_scid(chan, __le16_to_cpu(la.l2_cid));
else
err = l2cap_add_psm(chan, &la.l2_bdaddr, la.l2_psm);
@@ -123,7 +123,8 @@ static int l2cap_sock_connect(struct socket *sock, struct sockaddr *addr, int al
if (la.l2_cid && la.l2_psm)
return -EINVAL;
- err = l2cap_chan_connect(chan, la.l2_psm, la.l2_cid, &la.l2_bdaddr);
+ err = l2cap_chan_connect(chan, la.l2_psm, __le16_to_cpu(la.l2_cid),
+ &la.l2_bdaddr);
if (err)
return err;
diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index 7fcff88..4ef275c 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -2523,13 +2523,18 @@ static int set_fast_connectable(struct sock *sk, struct hci_dev *hdev,
if (cp->val) {
type = PAGE_SCAN_TYPE_INTERLACED;
- acp.interval = 0x0024; /* 22.5 msec page scan interval */
+
+ /* 22.5 msec page scan interval */
+ acp.interval = __constant_cpu_to_le16(0x0024);
} else {
type = PAGE_SCAN_TYPE_STANDARD; /* default */
- acp.interval = 0x0800; /* default 1.28 sec page scan */
+
+ /* default 1.28 sec page scan */
+ acp.interval = __constant_cpu_to_le16(0x0800);
}
- acp.window = 0x0012; /* default 11.25 msec page scan window */
+ /* default 11.25 msec page scan window */
+ acp.window = __constant_cpu_to_le16(0x0012);
err = hci_send_cmd(hdev, HCI_OP_WRITE_PAGE_SCAN_ACTIVITY, sizeof(acp),
&acp);
@@ -2936,7 +2941,7 @@ int mgmt_device_connected(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 link_type,
name, name_len);
if (dev_class && memcmp(dev_class, "\0\0\0", 3) != 0)
- eir_len = eir_append_data(&ev->eir[eir_len], eir_len,
+ eir_len = eir_append_data(ev->eir, eir_len,
EIR_CLASS_OF_DEV, dev_class, 3);
put_unaligned_le16(eir_len, &ev->eir_len);
diff --git a/net/mac80211/mlme.c b/net/mac80211/mlme.c
index 576fb25..f76da5b 100644
--- a/net/mac80211/mlme.c
+++ b/net/mac80211/mlme.c
@@ -3387,8 +3387,7 @@ int ieee80211_mgd_assoc(struct ieee80211_sub_if_data *sdata,
*/
printk(KERN_DEBUG "%s: waiting for beacon from %pM\n",
sdata->name, ifmgd->bssid);
- assoc_data->timeout = jiffies +
- TU_TO_EXP_TIME(req->bss->beacon_interval);
+ assoc_data->timeout = TU_TO_EXP_TIME(req->bss->beacon_interval);
} else {
assoc_data->have_beacon = true;
assoc_data->sent_assoc = false;
diff --git a/net/nfc/llcp/commands.c b/net/nfc/llcp/commands.c
index 7b76eb7..ef10ffc 100644
--- a/net/nfc/llcp/commands.c
+++ b/net/nfc/llcp/commands.c
@@ -474,7 +474,7 @@ int nfc_llcp_send_i_frame(struct nfc_llcp_sock *sock,
while (remaining_len > 0) {
- frag_len = min_t(u16, local->remote_miu, remaining_len);
+ frag_len = min_t(size_t, local->remote_miu, remaining_len);
pr_debug("Fragment %zd bytes remaining %zd",
frag_len, remaining_len);
@@ -497,7 +497,7 @@ int nfc_llcp_send_i_frame(struct nfc_llcp_sock *sock,
release_sock(sk);
remaining_len -= frag_len;
- msg_ptr += len;
+ msg_ptr += frag_len;
}
kfree(msg_data);
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index e49da27..f432c57 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -1294,6 +1294,11 @@ static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
goto bad_res;
}
+ if (!netif_running(netdev)) {
+ result = -ENETDOWN;
+ goto bad_res;
+ }
+
nla_for_each_nested(nl_txq_params,
info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
rem_txq_params) {
@@ -6384,7 +6389,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_get_key,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6416,7 +6421,7 @@ static struct genl_ops nl80211_ops[] = {
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
.doit = nl80211_set_beacon,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6424,7 +6429,7 @@ static struct genl_ops nl80211_ops[] = {
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
.doit = nl80211_start_ap,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6432,7 +6437,7 @@ static struct genl_ops nl80211_ops[] = {
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
.doit = nl80211_stop_ap,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6448,7 +6453,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_set_station,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6464,7 +6469,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_del_station,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6497,7 +6502,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_del_mpath,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6505,7 +6510,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_set_bss,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6531,7 +6536,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_get_mesh_config,
.policy = nl80211_policy,
/* can be retrieved by unprivileged users */
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6664,7 +6669,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_setdel_pmksa,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6672,7 +6677,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_setdel_pmksa,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6680,7 +6685,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_flush_pmksa,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
@@ -6840,7 +6845,7 @@ static struct genl_ops nl80211_ops[] = {
.doit = nl80211_probe_client,
.policy = nl80211_policy,
.flags = GENL_ADMIN_PERM,
- .internal_flags = NL80211_FLAG_NEED_NETDEV |
+ .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
NL80211_FLAG_NEED_RTNL,
},
{
diff --git a/net/wireless/wext-core.c b/net/wireless/wext-core.c
index 0af7f54..af648e0 100644
--- a/net/wireless/wext-core.c
+++ b/net/wireless/wext-core.c
@@ -780,8 +780,10 @@ static int ioctl_standard_iw_point(struct iw_point *iwp, unsigned int cmd,
if (cmd == SIOCSIWENCODEEXT) {
struct iw_encode_ext *ee = (void *) extra;
- if (iwp->length < sizeof(*ee) + ee->key_len)
- return -EFAULT;
+ if (iwp->length < sizeof(*ee) + ee->key_len) {
+ err = -EFAULT;
+ goto out;
+ }
}
}
--
John W. Linville Someday the world will need a hero, and you
linville@tuxdriver.com might be all we have. Be ready.
[-- Attachment #2: Type: application/pgp-signature, Size: 836 bytes --]
^ permalink raw reply related
* Re: [PATCH net-next] udp: intoduce udp_encap_needed static_key
From: Simon Horman @ 2012-04-12 14:35 UTC (permalink / raw)
To: Eric Dumazet
Cc: dev-yBygre7rU0TnMu66kgdUjQ, netdev-u79uwXL29TY76Z2rM5mHXA,
David Miller
In-Reply-To: <1334221528.5300.6008.camel@edumazet-glaptop>
On Thu, Apr 12, 2012 at 11:05:28AM +0200, Eric Dumazet wrote:
> Most machines dont use UDP encapsulation (L2TP)
>
> Adds a static_key so that udp_queue_rcv_skb() doesnt have to perform a
> test if L2TP never setup the encap_rcv on a socket.
>
> Idea of this patch came after Simon Horman proposal to add a hook on TCP
> as well.
>
> If static_key is not yet enabled, the fast path does a single JMP .
>
> When static_key is enabled, JMP destination is patched to reach the real
> encap_type/encap_rcv logic, possibly adding cache misses.
Thanks Eric,
I have not had a chance to test your code, though it should be easy enough
to do so in the context of Open vSwitch as its CAPWAP implementation makes
use of UDP's encap_rcv (which is how I arrived at adding hook to TCP to
implement STT for Open vSwtich).
I have incorporated your static_key code into a new version of my TCP
encap_rcv patch and that does appear to work. I will post it ASAP.
>
> Signed-off-by: Eric Dumazet <eric.dumazet-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
> Cc: Simon Horman <horms-/R6kz+dDXgpPR4JQBCEnsQ@public.gmane.org>
> Cc: dev-yBygre7rU0TnMu66kgdUjQ@public.gmane.org
> ---
> include/net/udp.h | 1 +
> net/ipv4/udp.c | 12 +++++++++++-
> net/l2tp/l2tp_core.c | 1 +
> 3 files changed, 13 insertions(+), 1 deletion(-)
>
> diff --git a/include/net/udp.h b/include/net/udp.h
> index 5d606d9..9671f5f 100644
> --- a/include/net/udp.h
> +++ b/include/net/udp.h
> @@ -267,4 +267,5 @@ extern void udp_init(void);
> extern int udp4_ufo_send_check(struct sk_buff *skb);
> extern struct sk_buff *udp4_ufo_fragment(struct sk_buff *skb,
> netdev_features_t features);
> +extern void udp_encap_enable(void);
> #endif /* _UDP_H */
> diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
> index fe14105..ad1e0dd 100644
> --- a/net/ipv4/udp.c
> +++ b/net/ipv4/udp.c
> @@ -107,6 +107,7 @@
> #include <net/checksum.h>
> #include <net/xfrm.h>
> #include <trace/events/udp.h>
> +#include <linux/static_key.h>
> #include "udp_impl.h"
>
> struct udp_table udp_table __read_mostly;
> @@ -1379,6 +1380,14 @@ static int __udp_queue_rcv_skb(struct sock *sk, struct sk_buff *skb)
>
> }
>
> +static struct static_key udp_encap_needed __read_mostly;
> +void udp_encap_enable(void)
> +{
> + if (!static_key_enabled(&udp_encap_needed))
> + static_key_slow_inc(&udp_encap_needed);
> +}
> +EXPORT_SYMBOL(udp_encap_enable);
> +
> /* returns:
> * -1: error
> * 0: success
> @@ -1400,7 +1409,7 @@ int udp_queue_rcv_skb(struct sock *sk, struct sk_buff *skb)
> goto drop;
> nf_reset(skb);
>
> - if (up->encap_type) {
> + if (static_key_false(&udp_encap_needed) && up->encap_type) {
> int (*encap_rcv)(struct sock *sk, struct sk_buff *skb);
>
> /*
> @@ -1760,6 +1769,7 @@ int udp_lib_setsockopt(struct sock *sk, int level, int optname,
> /* FALLTHROUGH */
> case UDP_ENCAP_L2TPINUDP:
> up->encap_type = val;
> + udp_encap_enable();
> break;
> default:
> err = -ENOPROTOOPT;
> diff --git a/net/l2tp/l2tp_core.c b/net/l2tp/l2tp_core.c
> index 89ff8c6..f6732b6 100644
> --- a/net/l2tp/l2tp_core.c
> +++ b/net/l2tp/l2tp_core.c
> @@ -1424,6 +1424,7 @@ int l2tp_tunnel_create(struct net *net, int fd, int version, u32 tunnel_id, u32
> /* Mark socket as an encapsulation socket. See net/ipv4/udp.c */
> udp_sk(sk)->encap_type = UDP_ENCAP_L2TPINUDP;
> udp_sk(sk)->encap_rcv = l2tp_udp_encap_recv;
> + udp_encap_enable();
> }
>
> sk->sk_user_data = tunnel;
>
>
^ permalink raw reply
* [RFC v4] Add TCP encap_rcv hook
From: Simon Horman @ 2012-04-12 14:40 UTC (permalink / raw)
To: Eric Dumazet
Cc: dev-yBygre7rU0TnMu66kgdUjQ, netdev-u79uwXL29TY76Z2rM5mHXA,
David Miller
In-Reply-To: <20120412143552.GA8730-/R6kz+dDXgpPR4JQBCEnsQ@public.gmane.org>
This hook is based on a hook of the same name provided by UDP. It provides
a way for to receive packets that have a TCP header and treat them in some
alternate way.
It is intended to be used by an implementation of the STT tunneling
protocol within Open vSwtich's datapath. A prototype of such an
implementation has been made.
The STT draft is available at
http://tools.ietf.org/html/draft-davie-stt-01
My prototype STT implementation has been posted to the dev-UOEtcQmXneFl884UGnbwIQ@public.gmane.org
The second version can be found at:
http://www.mail-archive.com/dev-yBygre7rU0TnMu66kgdUjQ@public.gmane.org/msg09001.html
It needs to be updated to call tcp_encap_enable()
Cc: Eric Dumazet <eric.dumazet-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
Signed-off-by: Simon Horman <horms-/R6kz+dDXgpPR4JQBCEnsQ@public.gmane.org>
---
v4
* Make use of static_key,
a tonic for insanity suggested by Eric Dumazet
v3
* Replace more UDP references with TCP
* Move socket accesses to inside socket lock
and release lock on return.
v2
* Fix comment to refer to TCP rather than UDP
* Allow skb to continue traversing the stack if
the encap_rcv callback returns a positive value.
This is the same behaviour as the UDP hook.
---
include/linux/tcp.h | 3 +++
include/net/tcp.h | 1 +
net/ipv4/tcp_ipv4.c | 34 +++++++++++++++++++++++++++++++++-
3 files changed, 37 insertions(+), 1 deletion(-)
diff --git a/include/linux/tcp.h b/include/linux/tcp.h
index b6c62d2..7210b23 100644
--- a/include/linux/tcp.h
+++ b/include/linux/tcp.h
@@ -472,6 +472,9 @@ struct tcp_sock {
* contains related tcp_cookie_transactions fields.
*/
struct tcp_cookie_values *cookie_values;
+
+ /* For encapsulation sockets. */
+ int (*encap_rcv)(struct sock *sk, struct sk_buff *skb);
};
static inline struct tcp_sock *tcp_sk(const struct sock *sk)
diff --git a/include/net/tcp.h b/include/net/tcp.h
index f75a04d..f2c4ac0 100644
--- a/include/net/tcp.h
+++ b/include/net/tcp.h
@@ -1575,5 +1575,6 @@ static inline struct tcp_extend_values *tcp_xv(struct request_values *rvp)
extern void tcp_v4_init(void);
extern void tcp_init(void);
+extern void tcp_encap_enable(void);
#endif /* _TCP_H */
diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
index 3a25cf7..dadcec6 100644
--- a/net/ipv4/tcp_ipv4.c
+++ b/net/ipv4/tcp_ipv4.c
@@ -62,6 +62,7 @@
#include <linux/init.h>
#include <linux/times.h>
#include <linux/slab.h>
+#include <linux/static_key.h>
#include <net/net_namespace.h>
#include <net/icmp.h>
@@ -1657,6 +1658,14 @@ csum_err:
}
EXPORT_SYMBOL(tcp_v4_do_rcv);
+static struct static_key tcp_encap_needed __read_mostly;
+void tcp_encap_enable(void)
+{
+ if (!static_key_enabled(&tcp_encap_needed))
+ static_key_slow_inc(&tcp_encap_needed);
+}
+EXPORT_SYMBOL(tcp_encap_enable);
+
/*
* From tcp_input.c
*/
@@ -1666,6 +1675,7 @@ int tcp_v4_rcv(struct sk_buff *skb)
const struct iphdr *iph;
const struct tcphdr *th;
struct sock *sk;
+ struct tcp_sock *tp;
int ret;
struct net *net = dev_net(skb->dev);
@@ -1726,9 +1736,30 @@ process:
bh_lock_sock_nested(sk);
ret = 0;
+
+ tp = tcp_sk(sk);
+ if (static_key_false(&tcp_encap_needed)) {
+ int (*encap_rcv)(struct sock *sk, struct sk_buff *skb);
+ encap_rcv = ACCESS_ONCE(tp->encap_rcv);
+ if (encap_rcv != NULL) {
+ /*
+ * This is an encapsulation socket so pass the skb to
+ * the socket's tcp_encap_rcv() hook. Otherwise, just
+ * fall through and pass this up the TCP socket.
+ * up->encap_rcv() returns the following value:
+ * <=0 if skb was successfully passed to the encap
+ * handler or was discarded by it.
+ * >0 if skb should be passed on to TCP.
+ */
+ if (encap_rcv(sk, skb) <= 0) {
+ ret = 0;
+ goto unlock_sock;
+ }
+ }
+ }
+
if (!sock_owned_by_user(sk)) {
#ifdef CONFIG_NET_DMA
- struct tcp_sock *tp = tcp_sk(sk);
if (!tp->ucopy.dma_chan && tp->ucopy.pinned_list)
tp->ucopy.dma_chan = dma_find_channel(DMA_MEMCPY);
if (tp->ucopy.dma_chan)
@@ -1744,6 +1775,7 @@ process:
NET_INC_STATS_BH(net, LINUX_MIB_TCPBACKLOGDROP);
goto discard_and_relse;
}
+unlock_sock:
bh_unlock_sock(sk);
sock_put(sk);
--
1.7.9.5
^ permalink raw reply related
* Re: [PATCH 06/10] mac80211: Add sta_state to ethtool stats.
From: Ben Greear @ 2012-04-12 14:48 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, netdev
In-Reply-To: <1334202554.3788.9.camel@jlt3.sipsolutions.net>
On 04/11/2012 08:49 PM, Johannes Berg wrote:
> On Wed, 2012-04-11 at 10:52 -0700, greearb@candelatech.com wrote:
>> From: Ben Greear<greearb@candelatech.com>
>>
>> Helps to know how the station is doing in it's association
>> attempt.
>>
>> Signed-off-by: Ben Greear<greearb@candelatech.com>
>> ---
>> :100644 100644 bbaf564... a63834d... M net/mac80211/cfg.c
>> net/mac80211/cfg.c | 6 ++++--
>> 1 files changed, 4 insertions(+), 2 deletions(-)
>>
>> diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
>> index bbaf564..a63834d 100644
>> --- a/net/mac80211/cfg.c
>> +++ b/net/mac80211/cfg.c
>> @@ -118,7 +118,7 @@ static const char ieee80211_gstrings_sta_stats[][ETH_GSTRING_LEN] = {
>> "rx_duplicates", "rx_fragments", "rx_dropped",
>> "tx_packets", "tx_bytes", "tx_fragments",
>> "tx_filtered", "tx_retry_failed", "tx_retries",
>> - "beacon_loss", "txrate", "rxrate", "signal",
>> + "beacon_loss", "sta_state", "txrate", "rxrate", "signal",
>> "channel", "noise", "ch_time", "ch_time_busy",
>> "ch_time_ext_busy", "ch_time_rx", "ch_time_tx"
>> };
>> @@ -534,10 +534,12 @@ static void ieee80211_get_et_stats(struct wiphy *wiphy,
>> data[i++] += sta->beacon_loss_count;
>>
>> if (!do_once) {
>> - i += 3;
>> + i += 4;
>> goto after_once;
>> }
>>
>> + data[i++] = sta->sta_state;
>> +
>
> Gee, I wish it was easier to tell if you were adding it to the right
> spot in the list ... any way that could be made easier?
It would be nice, but I haven't thought of an easy way to do this,
and I haven't noticed any other drivers
that found a way.
I *could* add a lot of #defines and do something like: data[STA_STATE_IDX] = sta->state,
and maybe create the strings array at run-time using macros to map string to
an idx define instead of have a static array of char*. But, I'm not sure if
it's worth the effort.
Thanks,
Ben
>
> johannes
--
Ben Greear <greearb@candelatech.com>
Candela Technologies Inc http://www.candelatech.com
^ permalink raw reply
* Re: [PATCH 05/10] mac80211: Add more ethtools stats: survey, rates, etc
From: Ben Greear @ 2012-04-12 14:50 UTC (permalink / raw)
To: Johannes Berg
Cc: linux-wireless-u79uwXL29TY76Z2rM5mHXA,
netdev-u79uwXL29TY76Z2rM5mHXA
In-Reply-To: <1334202406.3788.8.camel-8upI4CBIZJIJvtFkdXX2HixXY32XiHfO@public.gmane.org>
On 04/11/2012 08:46 PM, Johannes Berg wrote:
> On Wed, 2012-04-11 at 10:52 -0700, greearb-my8/4N5VtI7c+919tysfdA@public.gmane.org wrote:
>
>> --- a/net/mac80211/cfg.c
>> +++ b/net/mac80211/cfg.c
>> @@ -19,6 +19,7 @@
>> #include "cfg.h"
>> #include "rate.h"
>> #include "mesh.h"
>> +#include "../wireless/core.h"
>
> NACK. Don't do that.
So, move the pertinent header stuff to linux/include/ieee80211.h ??
Thanks,
Ben
>
> johannes
--
Ben Greear <greearb-my8/4N5VtI7c+919tysfdA@public.gmane.org>
Candela Technologies Inc http://www.candelatech.com
--
To unsubscribe from this list: send the line "unsubscribe linux-wireless" in
the body of a message to majordomo-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
^ permalink raw reply
* Re: Kernel panic with bridge networking
From: Massimo cetra @ 2012-04-12 14:57 UTC (permalink / raw)
To: Eric Dumazet; +Cc: netdev, Peter Huang (Peng)
In-Reply-To: <1334235175.5300.6329.camel@edumazet-glaptop>
On 12/04/2012 14:52, Eric Dumazet wrote:
> On Thu, 2012-04-12 at 14:30 +0200, Massimo Cetra wrote:
>> Hello,
>>
>> i am experiencing a panic whose logs are attached (grabbed with netconsole).
>>
> Known issue, and we are waiting from a fix from Peter.
>
> https://lkml.org/lkml/2012/3/31/17
>
> Peter, any progress on your side ?
>
Thanks Eric,
is there a way to prvent those panics, meanwhile ?
I mean: i don't understand if it depends strictly on IPv6 or it has
other causes.
The same kernel with ipv6 enabled but without ipv6 is not actually
panic-ing ...
And thanks to Peter as well.
Massimo
^ permalink raw reply
* Re: [PATCH 08/10] mac80211: Support on-channel scan option.
From: Ben Greear @ 2012-04-12 15:03 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, netdev
In-Reply-To: <1334202356.3788.7.camel@jlt3.sipsolutions.net>
On 04/11/2012 08:45 PM, Johannes Berg wrote:
> On Wed, 2012-04-11 at 10:52 -0700, greearb@candelatech.com wrote:
>
>> static int __ieee80211_start_scan(struct ieee80211_sub_if_data *sdata,
>> struct cfg80211_scan_request *req)
>> @@ -438,10 +461,43 @@ static int __ieee80211_start_scan(struct ieee80211_sub_if_data *sdata,
>> local->scan_req = req;
>> local->scan_sdata = sdata;
>>
>> - if (local->ops->hw_scan)
>> + if (local->ops->hw_scan) {
>> __set_bit(SCAN_HW_SCANNING,&local->scanning);
>> - else
>> - __set_bit(SCAN_SW_SCANNING,&local->scanning);
>> + } else {
>> + /* If we are scanning only on the current channel, then
>> + * we do not need to stop normal activities
>> + */
>> + if ((req->n_channels == 1)&&
>> + (req->channels[0]->center_freq ==
>> + local->hw.conf.channel->center_freq)) {
>
> how about "else if {", then the indentation isn't so deep and you can
> have much nicer code in the entire block :)
>
>> + unsigned long next_delay;
>
> please add a blank line after variable declarations.
>
>> + }
>> + else {
>
> please read the coding style documentation
>
>> @@ -672,6 +704,12 @@ void ieee80211_scan_work(struct work_struct *work)
>>
>> sdata = local->scan_sdata;
>>
>> + /* When scanning on-channel, the first-callback means completeed. */
>
> typo "completed"
Ok, will fix all of that.
>> + if (test_bit(SCAN_ONCHANNEL_SCANNING,&local->scanning)) {
>> + aborted = test_and_clear_bit(SCAN_ABORTED,&local->scanning);
>> + goto out_complete;
>> + }
>
> how does the onchannel bit get cleared?
__ieee80211_scan_completed sets local->scanning to 0, and it
will WARN_ON if local->scanning is NOT zero when entering
the method, so I don't think I should clear it earlier.
> Shouldn't you be calling pre/post scan hooks?
Probably so...I'll add that. Doesn't look like ath9k uses
it, but maybe some other NIC does need it.
> I'm a bit divided over this. On the one hand, it seems like a mildly
> useful optimisation, on the other though it adds a bunch of complexity
> for multi-channel we've been thinking about... Not that we want to
> support multi-channel with SW scan anyway, but still.
It's just an optimization...maybe just add a check and do a regular scan
if multi-channel is active if it's difficult to just make it work with
multi-channel?
Thanks,
Ben
>
> johannes
--
Ben Greear <greearb@candelatech.com>
Candela Technologies Inc http://www.candelatech.com
^ permalink raw reply
* Re: [PATCH 05/10] mac80211: Add more ethtools stats: survey, rates, etc
From: Ben Greear @ 2012-04-12 15:23 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, netdev
In-Reply-To: <1334202406.3788.8.camel@jlt3.sipsolutions.net>
On 04/11/2012 08:46 PM, Johannes Berg wrote:
> On Wed, 2012-04-11 at 10:52 -0700, greearb@candelatech.com wrote:
>
>> --- a/net/mac80211/cfg.c
>> +++ b/net/mac80211/cfg.c
>> @@ -19,6 +19,7 @@
>> #include "cfg.h"
>> #include "rate.h"
>> #include "mesh.h"
>> +#include "../wireless/core.h"
>
> NACK. Don't do that.
Looks like whatever I needed has already been moved somewhere
proper...I can just delete that line and it compiles fine.
Thanks,
Ben
>
> johannes
--
Ben Greear <greearb@candelatech.com>
Candela Technologies Inc http://www.candelatech.com
^ permalink raw reply
* [PATCH] Fix missing mutex_lock/unlock
From: mjr @ 2012-04-12 15:26 UTC (permalink / raw)
To: davem; +Cc: sboyd, ben, netdev, Matt Renzelmann
From: Matt Renzelmann <mjr@cs.wisc.edu>
All calls to ks8851_rdreg* and ks8851_wrreg* should be protected
with the driver's lock mutex. A spurious interrupt may otherwise cause a
crash.
Signed-off-by: Matt Renzelmann <mjr@cs.wisc.edu>
---
Hello,
I'm new to the kernel development process so I hope I've not screwed
this up with this extra text. We found a potential issue using a new
driver testing tool called SymDrive. It looks legitimate to me, so
I'm reporting it. We hope to make this tool available in the future.
Please let me know if I should modify the patch or re-send without
this commentary. Thanks in advance for your patience.
drivers/net/ethernet/micrel/ks8851.c | 4 ++++
1 files changed, 4 insertions(+), 0 deletions(-)
diff --git a/drivers/net/ethernet/micrel/ks8851.c b/drivers/net/ethernet/micrel/ks8851.c
index c722aa6..fa2001a 100644
--- a/drivers/net/ethernet/micrel/ks8851.c
+++ b/drivers/net/ethernet/micrel/ks8851.c
@@ -1515,11 +1515,15 @@ static int __devinit ks8851_probe(struct spi_device *spi)
goto err_netdev;
}
+ mutex_lock(&ks->lock);
+
netdev_info(ndev, "revision %d, MAC %pM, IRQ %d, %s EEPROM\n",
CIDER_REV_GET(ks8851_rdreg16(ks, KS_CIDER)),
ndev->dev_addr, ndev->irq,
ks->rc_ccr & CCR_EEPROM ? "has" : "no");
+ mutex_unlock(&ks->lock);
+
return 0;
--
1.7.5.4
^ permalink raw reply related
* Re: [PATCH] net: smsc911x: fix RX FIFO fastforwarding when dropping packets
From: Will Deacon @ 2012-04-12 15:54 UTC (permalink / raw)
To: Eric Dumazet; +Cc: netdev@vger.kernel.org, Steve Glendinning
In-Reply-To: <1334239299.5300.6478.camel@edumazet-glaptop>
On Thu, Apr 12, 2012 at 03:01:39PM +0100, Eric Dumazet wrote:
> On Thu, 2012-04-12 at 14:47 +0100, Will Deacon wrote:
>
> >
> > I don't think we want an skb_reserve at all, since the hardware shifts the
> > data in the RX FIFO, meaning that we will read two bytes of 0 anyway before
> > valid data.
> >
> > > skb_put(skb, pktlength - 4);
> >
> > I can move the put here if you like, but we need to use pktwords << 2 to
> > make sure that we read the leading and trailing zeroes inserted by the
> > hardware.
>
> before calling linux stack, you'll have to skip those 2 bytes.
>
> This is skb_reserve() purpose.
Gotcha, so I can lose the pull too. Here's an updated patch with log, thanks
for the help.
Will
Author: Will Deacon <will.deacon@arm.com>
Date: Thu Apr 12 13:54:17 2012 +0100
net: smsc911x: fix skb handling in receive path
The SMSC911x driver resets the ->head, ->data and ->tail pointers in the
skb on the reset path in order to avoid buffer overflow due to packet
padding performed by the hardware.
This patch fixes the receive path so that the skb pointers are fixed up
after the data has been read from the device, The error path is also
fixed to use number of words consistently and prevent erroneous FIFO
fastforwarding when skipping over bad data.
Signed-off-by: Will Deacon <will.deacon@arm.com>
diff --git a/drivers/net/ethernet/smsc/smsc911x.c b/drivers/net/ethernet/smsc/smsc911x.c
index 4a69710..5aa2dbe 100644
--- a/drivers/net/ethernet/smsc/smsc911x.c
+++ b/drivers/net/ethernet/smsc/smsc911x.c
@@ -1166,10 +1166,8 @@ smsc911x_rx_counterrors(struct net_device *dev, unsigned int rxstat)
/* Quickly dumps bad packets */
static void
-smsc911x_rx_fastforward(struct smsc911x_data *pdata, unsigned int pktbytes)
+smsc911x_rx_fastforward(struct smsc911x_data *pdata, unsigned int pktwords)
{
- unsigned int pktwords = (pktbytes + NET_IP_ALIGN + 3) >> 2;
-
if (likely(pktwords >= 4)) {
unsigned int timeout = 500;
unsigned int val;
@@ -1233,7 +1231,7 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
continue;
}
- skb = netdev_alloc_skb(dev, pktlength + NET_IP_ALIGN);
+ skb = netdev_alloc_skb(dev, pktwords << 2);
if (unlikely(!skb)) {
SMSC_WARN(pdata, rx_err,
"Unable to allocate skb for rx packet");
@@ -1243,14 +1241,12 @@ static int smsc911x_poll(struct napi_struct *napi, int budget)
break;
}
- skb->data = skb->head;
- skb_reset_tail_pointer(skb);
+ pdata->ops->rx_readfifo(pdata,
+ (unsigned int *)skb->data, pktwords);
/* Align IP on 16B boundary */
skb_reserve(skb, NET_IP_ALIGN);
skb_put(skb, pktlength - 4);
- pdata->ops->rx_readfifo(pdata,
- (unsigned int *)skb->head, pktwords);
skb->protocol = eth_type_trans(skb, dev);
skb_checksum_none_assert(skb);
netif_receive_skb(skb);
@@ -1565,7 +1561,7 @@ static int smsc911x_open(struct net_device *dev)
smsc911x_reg_write(pdata, FIFO_INT, temp);
/* set RX Data offset to 2 bytes for alignment */
- smsc911x_reg_write(pdata, RX_CFG, (2 << 8));
+ smsc911x_reg_write(pdata, RX_CFG, (NET_IP_ALIGN << 8));
/* enable NAPI polling before enabling RX interrupts */
napi_enable(&pdata->napi);
^ permalink raw reply related
page: next (older) | prev (newer) | latest
- recent:[subjects (threaded)|topics (new)|topics (active)]
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox